Description
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.
Published: 2026-09-30
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (potential memory corruption)
Action: Patch
AI Analysis

Impact

Pexip Infinity prior to version 38.2, as well as releases 39.0, 39.1 and 40.0, contains an improper input validation flaw in the media handling component. The flaw allows a remote attacker to send a crafted media stream that can trigger memory corruption or cause the media engine to abort during processing, resulting in a denial of service. The description does not explicitly state a buffer overflow, but based on the nature of the input validation issue it is inferred that the corruption could arise from a buffer overflow or a similar memory overwrite.

Affected Systems

Pexip Infinity installations running any version before 38.2, and the 39.0, 39.1, and 40.0 releases are affected. All other releases are considered unaffected.

Risk and Exploitability

With a CVSS score of 7.7 this vulnerability is classified as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploit at this time. The likely attack vector is remote via the media interface; a malicious node can push the crafted media stream over an exposed network to trigger the denial of service.

Generated by OpenCVE AI on September 30, 2026 at 08:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to a version that contains the fix, such as a release newer than 40.0.
  • If a patch that addresses the media vulnerability is available for the current release, apply it immediately.
  • If an upgrade cannot be performed right away, restrict or disable media stream processing from untrusted sources to mitigate the denial‑of‑service risk.

Generated by OpenCVE AI on September 30, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted Media Stream in Pexip Infinity

Wed, 30 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-787
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T13:53:23.841Z

Reserved: 2026-09-30T02:59:52.583Z

Link: CVE-2026-103109

cve-icon Vulnrichment

Updated: 2026-09-30T13:53:19.461Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T03:17:00.073

Modified: 2026-09-30T16:44:39.840

Link: CVE-2026-103109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:30:08Z

Weaknesses