CRITICAL
irontec
CVE published 2026-09-12
CVE-2026-90558
A stack buffer overflow vulnerability exists in sngrep through version 1.8.4. The vulnerability is caused by SIP attribute formatting routines that do not properly handle header values exceeding the 255-byte buffer limit. This allows attackers to craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields, potentially leading to crashes or arbitrary code execution during packet p [truncated]