CVE-2025-66443: Input Validation
Published Dec 25, 2025
·Updated
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.
Affected Software
2 affected components
Pexip Infinity>=35.0<38.1
Pexip Pexip Infinity>=35.0<39.0
Event History
Dec 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66443?
The severity of CVE-2025-66443 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2025-66443?
To fix CVE-2025-66443, upgrade Pexip Infinity to version 39.0 or later.
3
What versions of Pexip Infinity are affected by CVE-2025-66443?
Pexip Infinity versions 35.0 through 38.1 are affected by CVE-2025-66443.
4
What type of attack does CVE-2025-66443 allow?
CVE-2025-66443 allows an attacker to trigger a software abort, resulting in a temporary denial of service.
5
Is proper input validation a concern in CVE-2025-66443?
Yes, CVE-2025-66443 is related to improper input validation in signalling for non-default configurations using Direct Media for WebRTC.