CVE-2026-103102 PUBLISHED

Assigner: mitre
Reserved: 30.09.2026 Published: 30.09.2026 Updated: 30.09.2026

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS Score: 8.6

Product Status

Vendor Pexip
Product Infinity
Versions Default: unaffected
  • affected from 0 to 41.0.0 (excl.)

References

Problem Types

  • CWE-770 Allocation of Resources Without Limits or Throttling CWE