OpenSIPS是OpenSIPS组织开源的一个 GPL 许可的 SIP 服务器实现。 OpenSIPS 3.6.6之前版本和4.0.0-rc1之前版本存在数字错误漏洞,该漏洞源于TCP消息分帧层在解析Content-Length标头时使用无符号整数运算且未进行溢出检查,可能导致未经身份验证的网络攻击者通过发送溢出的Content-Length值实现SIP消息走私,绕过前端SBC/代理安全策略,继承连接的认证上下文,并规避速率限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-45538 | 9.8 CRITICAL | OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
| CVE-2026-45100 | 9.1 CRITICAL | OpenSIPS: Buffer Overflow in Base64 Encode Transformation |
| CVE-2026-45537 | 9.1 CRITICAL | OpenSIPS: Global Buffer Overflow in construct_uri |
| CVE-2026-45084 | 8.7 HIGH | OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state |
| CVE-2026-45809 | 8.7 HIGH | OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI |
| CVE-2026-46334 | 8.7 HIGH | OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning |
| CVE-2026-45705 | 5.3 MEDIUM | OpenSIPS: OOB Read in Multipart Body Boundary Parsing |
No comments yet