CVE-2026-103109
Received Received - Intake

Improper Input Validation in Pexip Infinity Media Stream

Vulnerability report for CVE-2026-103109, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pexip infinity to 38.2 (exc)
pexip infinity 39.0
pexip infinity 39.1
pexip infinity 40.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Pexip Infinity versions before 38.2, plus 39.0, 39.1, and 40.0. It involves improper input validation in the media processing component, allowing a remote attacker to send a crafted media stream that triggers memory corruption or a software abort. This results in a denial of service by causing the system to crash or behave unpredictably.

Impact Analysis

The vulnerability can disrupt Pexip Infinity services by causing crashes or memory corruption when processing malicious media streams. This may lead to service outages, loss of availability for video conferencing or communication systems, and potential exposure of sensitive data if memory corruption occurs.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by disrupting the availability of communication systems, leading to potential data processing interruptions. A denial of service may cause delays or failures in handling personal or health data, violating availability requirements under these regulations.

Mitigation Strategies

Update Pexip Infinity to version 38.2 or later to address the improper input validation issue. Avoid using versions 39.0, 39.1, and 40.0 unless patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103109. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart