Sceawere
Vulnerability Detail
CVE-2026-103109UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pexip Infinity Media Memory Corruption
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 4h ago
- Vendor
- Pexip
- Product
- Infinity
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-09-30T03:17:00.073Z",
"pubdate": "2026-09-30T03:17:00.073Z",
"executiveSummary": "Pexip Infinity versions prior to 38.2, 39.0, 39.1, and 40.0 contain a critical vulnerability rooted in improper input validation within the media processing implementation.\nThis security flaw allows a remote, unauthenticated attacker to inject a maliciously crafted media stream, which triggers a memory corruption event or forces a software abort.\nThe primary impact of this vulnerability is a Denial of Service (DoS), effectively rendering the Pexip Infinity media services unavailable.\nThe flaw stems from the failure to correctly sanitize or validate incoming media data, leading to memory handling errors during stream parsing.\nRisk implications are high for environments relying on continuous availability of Pexip Infinity, as no specialized authentication is required to initiate the attack.\nThe exploitation capability is limited to triggering service disruptions through crashes, though the presence of memory corruption suggests the theoretical possibility of more severe exploitation vectors depending on specific environmental memory layouts.",
"technicalDetails": "The vulnerability is situated within the media processing layer of Pexip Infinity. It arises due to insufficient input validation mechanisms applied to media streams received by the application. Because media processing is frequently performed at the ingress point of the system, the lack of rigorous bounds checking or state validation creates a high-risk surface for remote exploitation.\nWhen an attacker sends a specially crafted media stream that violates the expected protocol specifications or internal data structure requirements, the media implementation enters an undefined state. During the processing of these malformed packets, the application fails to handle the input safely. This leads to a memory corruption event, which may manifest as an out-of-bounds access, a buffer overflow, or a logic error that the software recovery routines cannot handle gracefully.\nThe exploitation flow initiates with the attacker establishing or interacting with a media session managed by the Pexip Infinity platform. By injecting the crafted payload into the stream, the attacker influences the internal buffer management or parser state. The software, lacking proper validation, proceeds to process the data, resulting in a controlled abort—a forced exit or 'panic'—that terminates the process to prevent further instability. This directly results in a Denial of Service (DoS) for the affected media service.\nBecause the vulnerability occurs at the protocol processing level, it is accessible via the network to any attacker capable of sending media traffic to the affected Pexip Infinity node. No prior authentication is required to deliver the malicious stream, making the attack surface external and broad.\nThe technical core of this issue involves the interaction between the media implementation's memory allocator and the incoming data stream. The corruption of memory heap or stack structures during parsing provides the mechanism for the crash. While the immediate result is an abort, the underlying memory corruption could theoretically be leveraged by an sophisticated adversary to attempt control over the application's execution flow, depending on the specific memory layout and protection mechanisms enabled on the host system.\nAffected versions include all iterations prior to 38.2, as well as the 39.0, 39.1, and 40.0 releases. The vulnerability persists until these versions are updated to a non-vulnerable release provided by the vendor."
}