OpenSIPS是OpenSIPS组织开源的一个 GPL 许可的 SIP 服务器实现。 OpenSIPS 3.4.0-beta版本至3.6.6之前版本和4.0.0-beta版本至4.0.0-rc1之前版本存在缓冲区错误漏洞,该漏洞源于{s.b64encode}字符串转换过程中存在缓冲区溢出,base64编码扩展数据导致溢出,可能破坏相邻缓冲区数据,远程攻击者可通过发送包含大头部值的SIP消息触发。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-45538 | 9.8 CRITICAL | OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
| CVE-2026-45537 | 9.1 CRITICAL | OpenSIPS: Global Buffer Overflow in construct_uri |
| CVE-2026-45084 | 8.7 HIGH | OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state |
| CVE-2026-45809 | 8.7 HIGH | OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI |
| CVE-2026-46334 | 8.7 HIGH | OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning |
| CVE-2026-45103 | 7.5 HIGH | OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow |
| CVE-2026-45705 | 5.3 MEDIUM | OpenSIPS: OOB Read in Multipart Body Boundary Parsing |
No comments yet