Description
Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.
Published: 2026-09-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Pexip Infinity versions prior to 40.1 are affected by an improper input validation flaw in the signaling implementation. An attacker can send malformed signaling data, causing the application to abort and terminate processing. This abort results in a denial of service where the instance stops handling calls and may require a restart, impacting availability while leaving confidentiality and integrity unaffected.

Affected Systems

All installations of Pexip Infinity running any version earlier than 40.1 are vulnerable. No other Pexip products or later versions are known to be affected.

Risk and Exploitability

The CVSS score of 7.5 reflects a moderate to high risk primarily due to the service availability impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying limited evidence of active exploitation. Based on the description, it is inferred that an attacker can send malformed signaling data over the network to trigger the abort. The likely attack vector is inferred to involve network access to the signaling interface; a remote actor who can transmit crafted packets may cause the service to terminate without needing credentials.

Generated by OpenCVE AI on September 30, 2026 at 08:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Pexip Infinity patch 40.1 or later, which corrects the input‑validation flaw in the signaling implementation.
  • Restart the Pexip Infinity service after applying the update to clear any aborted state.
  • If an immediate update cannot be performed, block or restrict inbound traffic to the signalling ports using a firewall or network ACL to reduce the chance of malformed packets reaching the application.

Generated by OpenCVE AI on September 30, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Pexip Infinity Signaling Causes Denial of Service before 40.1

Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-617
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T02:17:33.057Z

Reserved: 2026-09-30T02:17:32.261Z

Link: CVE-2026-103100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T03:16:58.870

Modified: 2026-09-30T16:44:39.840

Link: CVE-2026-103100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:30:08Z

Weaknesses