← Vulnerability feed

Vulnerability record · CVE-2026-103102 · published 30 September 2026

CVE-2026-103102: Pexip infinity allocation without limits vulnerability

Pexip · Pexip Infinity

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

8.6 CVSS 3.1 High EPSS 0.32% · top 77.3% CWE-770 · Allocation without limits
8.6CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
5 Oct 2026Last modified by NVD

Description

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-103102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-103110Pexip infinity out-of-bounds write vulnerabilityPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely…EPSS 0.61%9.8CVE-2020-11805Pexip infinity improper input validation vulnerabilityPexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.EPSS 1.4%9.8CVE-2015-4719Pexip infinity improper privilege management vulnerabilityThe client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.EPSS 1.5%9.8CVE-2017-6551Pexip infinity improper input validation vulnerabilityPexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Co…EPSS 3.5%9.4CVE-2026-103109Pexip infinity out-of-bounds write vulnerabilityPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attac…EPSS 0.24%9.1CVE-2025-59683Pexip infinity incorrect authorization vulnerabilityPexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega…EPSS 0.33%8.8CVE-2026-103105Pexip infinity incorrect authorization vulnerabilityPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with …EPSS 0.18%8.2CVE-2022-27933Pexip infinity vulnerabilityPexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2026-103102), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.