
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-32096 is an improper input validation vulnerability in Pexip Infinity's signaling component that allows an unauthenticated remote attacker to trigger a software abort, resulting in a denial of service. It affects Pexip Infinity versions 33.0 through 37.0 (before 37.1) and was published on December 25, 2025. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Pexip Security Bulletins).
The root cause is classified as CWE-617 (Reachable Assertion), meaning the software contains an assertion that can be triggered by attacker-controlled input through the signaling interface. An unauthenticated remote attacker can send specially crafted signaling traffic over the network to reach the vulnerable assertion, causing the process to abort. No authentication, privileges, or user interaction are required, and the attack complexity is low. No public proof-of-concept or detailed technical write-up has been identified at this time (Red Hat CVE, Pexip Security Bulletins).
Successful exploitation causes the affected Pexip Infinity conferencing service to crash (software abort), resulting in complete unavailability of conferencing services for all users. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged (the crash is contained to the affected service). Organizations relying on Pexip Infinity for video conferencing would experience a full service outage until the process is restarted or the system is remediated (Red Hat CVE, Pexip Security Bulletins).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of reporting. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though it was referenced in a CISA vulnerability bulletin for the week of December 22, 2025 (CISA Bulletin). The EPSS score is approximately 0.04%, indicating a low probability of exploitation in the near term. Despite the low exploitation likelihood, the ease of remote unauthenticated exploitation (low complexity, no interaction required) makes patching a priority (Red Hat CVE).
Pexip has released version 37.1 which addresses this vulnerability; all users running Pexip Infinity 33.0 through 37.0 should upgrade immediately (Pexip Security Bulletins). As a temporary workaround until patching is feasible, administrators should consider applying network-level access controls to restrict signaling traffic from untrusted or external sources. Prioritize this update given the high availability impact and the ease of unauthenticated remote exploitation.
The vulnerability received routine coverage from vulnerability tracking platforms and security news aggregators following its December 25, 2025 publication. Social media mentions were observed on Mastodon and Bluesky from automated CVE tracking accounts. No notable independent researcher commentary or vendor statements beyond the official Pexip security bulletin have been identified (Pexip Security Bulletins).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."