Description
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
Published: 2026-09-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply update
AI Analysis

Impact

Pexip Infinity contains an improper input validation flaw in its media implementation that allows a remote attacker to trigger a software abort, resulting in a denial of service. The vulnerability is rooted in the handling of media stream data, where unexpected or malformed input can compel the system to terminate processes without graceful recovery, disrupting communication services for users.

Affected Systems

Versions of Pexip Infinity older than 38.2, as well as the 39.0, 39.1 and 40.0 releases, are vulnerable. All deployments of these releases are at risk unless updated to a patched version released after these milestones.

Risk and Exploitability

The flaw scores a CVSS base of 7.5, indicating high severity, and it is exploitable from the network via remote input to the media component. Although a specific EPSS score is not available, the lack of a CISA KEV listing does not negate the urgency; the remote nature of the exploit coupled with the ability to bring the system down makes this a significant threat. An attacker can initiate a denial-of-service by sending crafted media packets, potentially overwhelming or crashing the service and denying business continuity for users.

Generated by OpenCVE AI on September 30, 2026 at 07:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to the latest stable release (e.g., version 40.1 or newer) that resolves the input validation issue.
  • If an upgrade cannot be performed immediately, isolate the media services behind a firewall and restrict external access to the affected endpoints to limit the attack surface.
  • Continuously monitor system logs and set alerts for unexpected aborts or crashes to detect and respond to potential denial-of-service attempts.

Generated by OpenCVE AI on September 30, 2026 at 07:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-617
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T02:49:52.530Z

Reserved: 2026-09-30T02:49:51.767Z

Link: CVE-2026-103108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T03:16:59.920

Modified: 2026-09-30T03:16:59.920

Link: CVE-2026-103108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:30:17Z

Weaknesses