Impact
Pexip Infinity is vulnerable to improper input validation in its signaling layer. An attacker who can connect to a gateway call from a WebRTC or API client can send crafted input that causes the software to abort. The abort response yields a denial of service, preventing the affected instance from processing subsequent requests until it is restarted. The flaw involves an out‑of‑resources condition and is listed as CWE‑770.
Affected Systems
The vulnerability applies to all installations of Pexip Infinity running any version prior to 41.0. No specific minor releases are mentioned, so all earlier builds are affected until the vendor releases a patch for 41.0 or newer.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and while EPSS data is missing, the absence of a KEV listing does not diminish potential impact. Exploitation requires only the ability to initiate a gateway call, a capability that could be granted to unauthenticated or low‑privileged clients if not properly controlled. Attackers can repeatedly trigger the abort to exhaust server resources, effectively taking the service offline. Given the limited prerequisites, the likelihood of successful exploitation is significant for exposed deployments.
OpenCVE Enrichment