Intel

AIKIDO-2026-10196

janus-gateway is vulnerable to Use after free

Use after free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

47

Medium Risk

This Affects:

JSjanus-gateway
0.0.1 - 1.3.3
Fixed in 1.4.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a use-after-free condition in SIP session helper handling. Improper cleanup of helper and master session references can leave dangling pointers, which may lead to crashes or potentially allow memory corruption when the freed objects are accessed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

janus-gateway is vulnerable to Use after free in versions 0.0.1 - 1.3.3.

How to fix this

Upgrade the janus-gateway library to the patch version.