CVE-2026-103108: Input Validation
Published Sep 30, 2026
·Updated
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
Affected Software
1 affected component
Pexip Infinity<38.2, =39.0, =39.1, =40.0
Event History
Sep 30, 2026
CVE Published
via MITRE·02:49 AM
Data Sourced
via MITRE·02:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Pexip Infinity releases need remediation?
Pexip Infinity releases before 38.2, as well as releases 39.0, 39.1, and 40.0, are affected. Organizations running any of these versions should consult the vendor security bulletin for remediation guidance.
2
Does exploitation require authentication or user interaction?
No. The vulnerability is remotely exploitable with low attack complexity and requires neither privileges nor user interaction.
3
What is the expected impact of a successful attack?
A remote attacker can cause a software abort in the media implementation, resulting in a denial of service. The provided severity vector indicates no confidentiality or integrity impact.