cbcvebase.

Pexip Infinity vulnerabilities

24 known vulnerabilities affecting pexip/infinity.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH19MEDIUM2

Vulnerabilities

Page 1 of 2
CVE-2026-103110P2CRITICALCVSS 9.8fixed in 38.2.0v39.0.0+2 more2026-09-30
CVE-2026-103110 [CRITICAL] CWE-787 CVE-2026-103110: Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
nvd
CVE-2026-103109P3CRITICALCVSS 9.4fixed in 38.2.0v39.0.0+2 more2026-09-30
CVE-2026-103109 [CRITICAL] CWE-787 CVE-2026-103109: Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in th Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve mem
nvd
CVE-2026-103105P3HIGHCVSS 8.8fixed in 38.2.0v39.0.0+2 more2026-09-30
CVE-2026-103105 [HIGH] CWE-863 CVE-2026-103105: Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a pr Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
nvd
CVE-2025-59683P3CRITICALCVSS 9.1≥ 15.0, < 38.12025-12-25
CVE-2025-59683 [CRITICAL] CWE-863 CVE-2025-59683: Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.
nvd
CVE-2026-103102P3HIGHCVSS 8.6fixed in 41.0.02026-09-30
CVE-2026-103102 [HIGH] CWE-770 CVE-2026-103102: Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
nvd
CVE-2026-103106P3HIGHCVSS 7.8fixed in 38.2.0v39.0.0+2 more2026-09-30
CVE-2026-103106 [HIGH] CWE-669 CVE-2026-103106: Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation with Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulne
nvd
CVE-2025-66377P3HIGHCVSS 7.5fixed in 39.02025-12-25
CVE-2025-66377 [HIGH] CWE-306 CVE-2025-66377: Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.
nvd
CVE-2026-103101P3HIGHCVSS 7.5≥ 30.0.0, < 41.0.02026-09-30
CVE-2026-103101 [HIGH] CWE-770 CVE-2026-103101: Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web ser Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
nvd
CVE-2026-103108P3HIGHCVSS 7.5fixed in 38.2.0v39.0.0+2 more2026-09-30
CVE-2026-103108 [HIGH] CWE-617 CVE-2026-103108: Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in t Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
nvd
CVE-2026-103099P3HIGHCVSS 7.5≥ 18.0.0, < 41.1.02026-09-30
CVE-2026-103099 [HIGH] CWE-617 CVE-2026-103099: Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.
nvd
CVE-2026-103104P3HIGHCVSS 7.5fixed in 38.2.0v39.0.0+2 more2026-09-30
CVE-2026-103104 [HIGH] CWE-617 CVE-2026-103104: Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in th Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.
nvd
CVE-2026-103100P3HIGHCVSS 7.5fixed in 40.1.02026-09-30
CVE-2026-103100 [HIGH] CWE-617 CVE-2026-103100: Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.
nvd
CVE-2025-32095P3HIGHCVSS 7.5fixed in 37.02025-12-25
CVE-2025-32095 [HIGH] CWE-617 CVE-2025-32095: Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.
nvd
CVE-2025-66379P3HIGHCVSS 7.5fixed in 39.02025-12-25
CVE-2025-66379 [HIGH] CWE-617 CVE-2025-66379: Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a rem Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.
nvd
CVE-2025-32096P3HIGHCVSS 7.5≥ 33.0, < 37.12025-12-25
CVE-2025-32096 [HIGH] CWE-617 CVE-2025-32096: Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.
nvd
CVE-2025-48704P3HIGHCVSS 7.5≥ 35.0, < 38.02025-12-25
CVE-2025-48704 [HIGH] CWE-617 CVE-2025-48704: Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.
nvd
CVE-2025-66378P3HIGHCVSS 7.5≥ 38.0, < 39.02025-12-25
CVE-2025-66378 [HIGH] CWE-863 CVE-2025-66378: Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.
nvd
CVE-2021-32545P3HIGHCVSS 7.5fixed in 262022-01-15
CVE-2021-32545 [HIGH] CWE-20 CVE-2021-32545: Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation. Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
nvd
CVE-2021-42555P3HIGHCVSS 7.5≥ 25.0, < 26.22022-01-15
CVE-2021-42555 [HIGH] CWE-20 CVE-2021-42555: Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
nvd
CVE-2021-33498P3HIGHCVSS 7.5fixed in 262022-01-15
CVE-2021-33498 [HIGH] CWE-20 CVE-2021-33498: Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation ( Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
nvd
Pexip Infinity vulnerabilities | cvebase