cbcvebase.

Pexip Infinity vulnerabilities

24 known vulnerabilities affecting pexip/infinity.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH19MEDIUM2

Vulnerabilities

Page 2 of 2
CVE-2021-33499P3HIGHCVSS 7.5fixed in 262022-01-15
CVE-2021-33499 [HIGH] CWE-20 CVE-2021-33499: Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation ( Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
nvd
CVE-2021-35969P3HIGHCVSS 7.5≥ 22.0, < 262022-01-15
CVE-2021-35969 [HIGH] CWE-20 CVE-2021-35969: Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-s Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
nvd
CVE-2025-49088P4MEDIUMCVSS 5.9≥ 32.0, < 37.22025-12-25
CVE-2025-49088 [MEDIUM] CWE-617 CVE-2025-49088: Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.
nvd
CVE-2025-66443P4MEDIUMCVSS 5.3≥ 35.0, < 39.02025-12-25
CVE-2025-66443 [MEDIUM] CWE-617 CVE-2025-66443: Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media fo Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.
nvd
Pexip Infinity vulnerabilities | cvebase