
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66443 is an Improper Input Validation vulnerability in Pexip Infinity affecting versions 35.0 through 38.1 (before 39.0) that allows a remote, unauthenticated attacker to trigger a software abort, resulting in a temporary denial of service. The vulnerability is limited to non-default configurations that use Direct Media for WebRTC. It was published on December 25, 2025, with a patch released in version 39.0. The CVSS v3.1 base score is 5.3 (Medium) per NVD, though ENISA's EUVD rates it 7.5 (High) based on a higher availability impact assessment (Red Hat CVE, Pexip Security Bulletins).
The root cause is classified as CWE-617 (Reachable Assertion) — a condition where a reachable assertion in the signalling code can be triggered by malformed or unexpected input, causing the process to abort. An attacker sends specially crafted signalling messages over the network targeting Pexip Infinity instances configured to use Direct Media for WebRTC; no authentication or user interaction is required. The vulnerability exists only in non-default configurations, meaning standard deployments without Direct Media for WebRTC are not affected. No public proof-of-concept code has been identified (Red Hat CVE, Pexip Security Bulletins).
Successful exploitation causes a software abort in the affected Pexip Infinity service, resulting in a temporary denial of service that renders the conferencing platform unavailable until the service is restarted. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. The scope is restricted to organizations running Pexip Infinity versions 35.0–38.1 with Direct Media for WebRTC enabled, a non-default configuration (Red Hat CVE).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The EPSS score is approximately 0.04%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no authentication and no user interaction, but is constrained to a specific non-default configuration, limiting the exposed attack surface (Red Hat CVE, Pexip Security Bulletins).
Pexip has released version 39.0 which resolves this vulnerability; organizations running Pexip Infinity 35.0 through 38.1 should upgrade immediately (Pexip Security Bulletins). If immediate patching is not feasible, organizations should verify whether Direct Media for WebRTC is enabled — if this non-default feature is not in use, the risk is mitigated without configuration changes. As an additional control, implement network-level access controls to restrict signalling traffic to trusted sources only, and monitor system logs for unexpected abort events or service restarts that could indicate exploitation attempts.
The vulnerability received limited community attention, with automated CVE tracking accounts on Bluesky and Mastodon noting the disclosure. No significant vendor statements beyond the Pexip security bulletin or notable independent researcher commentary have been identified. Coverage has been limited to vulnerability aggregation sites and security news digests.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."