Description
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.
Published: 2026-09-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Improper input validation in Pexip Infinity's media implementation allows a remote attacker to cause a software abort, resulting in a denial of service. The CWE-617 vulnerability indicates that untrusted input is used without proper filtering, leading to application failure. This flaw can disable VoIP, video, or other media services that rely on the affected components, potentially disrupting communications for all users on the system.

Affected Systems

All Pexip Infinity deployments running versions before 38.2, as well as the 39.0, 39.1, and 40.0 releases, are affected. Versions 38.2 and later that are not 39.0, 39.1, or 40.0 are presumed not to contain the issue, but the latest stable release should always be verified.

Risk and Exploitability

The CVSS score of 7.5 classifies this vulnerability as high severity. No EPSS score is available, so the exact likelihood of exploitation is unclear, but the fact that it is not listed in the CISA KEV catalog suggests that there are currently no publicly known exploits. The attack vector is remote, targeting the media implementation over the network. An attacker could trigger the abort by sending a crafted request from outside the network or from a compromised internal host, causing a denial of service that affects all users of the system.

Generated by OpenCVE AI on September 30, 2026 at 07:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to a version that is not affected (e.g., a release after 38.2 that is not 39.0, 39.1, or 40.0), ensuring the media implementation is patched against the validation flaw.
  • Restrict inbound traffic to the media endpoints by using a firewall or network segmentation to limit exposure to trusted IP addresses, reducing the attack surface for remote exploitation.
  • Monitor system logs and media service health for signs of abnormal aborts or denial of service events, and apply any vendor‑supplied workaround or security advisory if and when it becomes available.

Generated by OpenCVE AI on September 30, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-617
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T13:53:49.579Z

Reserved: 2026-09-30T02:35:06.247Z

Link: CVE-2026-103104

cve-icon Vulnrichment

Updated: 2026-09-30T13:53:45.592Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T03:16:59.467

Modified: 2026-09-30T16:44:39.840

Link: CVE-2026-103104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T09:00:07Z

Weaknesses