CVE-2026-103102
Received Received - Intake

Improper Input Validation in Pexip Infinity Leading to DoS

Vulnerability report for CVE-2026-103102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pexip infinity to 41.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in Pexip Infinity before version 41.0. It occurs due to improper input validation in the signaling implementation, allowing a remote attacker to trigger a software abort by accessing a gateway call from a WebRTC or API client.

Detection Guidance

Detection of this vulnerability requires monitoring for abnormal call signaling patterns or software aborts in Pexip Infinity systems. Check logs for gateway call disconnections or crashes from WebRTC/API clients. No specific commands are provided in the available context.

Impact Analysis

The vulnerability can cause a denial of service, meaning systems may become unavailable or crash. If exploited, it could disrupt communication services relying on Pexip Infinity, such as video conferencing or API-based integrations.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. The vulnerability causes a denial of service via improper input validation, which could disrupt services but does not inherently violate these regulations.

Mitigation Strategies

Update Pexip Infinity to version 41.0 or later to address the improper input validation issue. Ensure all gateways and WebRTC/API clients are updated to prevent exploitation leading to denial of service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103102. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart