Description
Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
Published: 2026-09-30
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Pexip Infinity is vulnerable to improper input validation in its signaling layer. An attacker who can connect to a gateway call from a WebRTC or API client can send crafted input that causes the software to abort. The abort response yields a denial of service, preventing the affected instance from processing subsequent requests until it is restarted. The flaw involves an out‑of‑resources condition and is listed as CWE‑770.

Affected Systems

The vulnerability applies to all installations of Pexip Infinity running any version prior to 41.0. No specific minor releases are mentioned, so all earlier builds are affected until the vendor releases a patch for 41.0 or newer.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and while EPSS data is missing, the absence of a KEV listing does not diminish potential impact. Exploitation requires only the ability to initiate a gateway call, a capability that could be granted to unauthenticated or low‑privileged clients if not properly controlled. Attackers can repeatedly trigger the abort to exhaust server resources, effectively taking the service offline. Given the limited prerequisites, the likelihood of successful exploitation is significant for exposed deployments.

Generated by OpenCVE AI on September 30, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to version 41.0 or later to remove the validation flaw.
  • Restrict access to the WebRTC/API gateway, ensuring only trusted clients can establish calls and limiting public exposure of the signaling interface.
  • Apply network-level rate limiting or firewall rules to detect and block repeated abort attempts, reducing the risk of a denial‑of‑service attack.

Generated by OpenCVE AI on September 30, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in Signaling

Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-770
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T02:29:04.346Z

Reserved: 2026-09-30T02:29:03.549Z

Link: CVE-2026-103102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T03:16:59.307

Modified: 2026-09-30T03:16:59.307

Link: CVE-2026-103102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling