Improper Validation of Syntactic Correctness of Input Affecting asterisk package, versions [,18.9-cert17)[,18.26.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ASTERISK-12301686
  • published31 Aug 2025
  • disclosed28 Aug 2025
  • creditUnknown

Introduced: 28 Aug 2025

NewCVE-2025-54995  (opens in a new tab)
CWE-1286  (opens in a new tab)

How to fix?

Upgrade asterisk to version 18.9-cert17, 18.26.4 or higher.

Overview

Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input via the improper termination of RTP sessions. An attacker can cause resource exhaustion by initiating and not properly terminating multiple RTP sessions, leading to a leak of UDP ports and internal resources.

CVSS Base Scores

version 4.0
version 3.1