← Vulnerability feed

Vulnerability record · CVE-2025-66379 · published 25 December 2025

CVE-2025-66379: Pexip infinity vulnerability

Pexip · Pexip Infinity

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

7.5 CVSS 3.1 High EPSS 0.37% · top 71.4% CWE-617 · CWE-617
7.5CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66379 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-11805Pexip infinity improper input validation vulnerabilityPexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.EPSS 1.4%9.8CVE-2015-4719Pexip infinity improper privilege management vulnerabilityThe client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.EPSS 1.5%9.8CVE-2017-6551Pexip infinity improper input validation vulnerabilityPexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Co…EPSS 3.5%9.1CVE-2025-59683Pexip infinity incorrect authorization vulnerabilityPexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega…EPSS 0.33%8.2CVE-2022-26656Pexip infinity vulnerabilityPexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.EPSS 1.1%8.2CVE-2022-27933Pexip infinity vulnerabilityPexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.EPSS 1.1%7.5CVE-2025-66377Pexip infinity missing authentication for critical function vulnerabilityPexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access…EPSS 0.21%7.5CVE-2025-66378Pexip infinity incorrect authorization vulnerabilityPexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-66379), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.