PatchSiren

OpenSIPS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenSIPS CVE published 2026-08-05

CVE-2026-46334

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, is affected by a denial of service vulnerability in its SDP bandwidth-line parsing logic. The vulnerability occurs in versions prior to 3.6.6 and 4.0.0-rc1. An unauthenticated remote attacker can trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing by sending a SIP req [truncated]

HIGH OpenSIPS CVE published 2026-08-05

CVE-2026-45809

The CVE-2026-45809 vulnerability is a denial of service issue in OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1, affecting deployments that expose handle_subscribe() and allow watcherinfo (presence.winfo) generation. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a long From URI, triggering presence.winfo watcherinfo XML generation and crashing the Op [truncated]

MEDIUM OpenSIPS CVE published 2026-08-05

CVE-2026-45705

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a vulnerability in versions prior to 3.6.6 and 4.0.0-rc1. The find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. This occurs when a SIP message has a Content-Type: multipart/mixed with a boundary parameter and its body contains -- withi [truncated]

CRITICAL OpenSIPS CVE published 2026-08-04

CVE-2026-45537

The OpenSIPS server implementation has a buffer overflow vulnerability in the construct_uri() function, which can be exploited by an attacker-controlled username to corrupt adjacent global data. This issue affects OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1. The vulnerability has a CVSS score of 9.1 and is considered CRITICAL. OpenSIPS users and administrators should be aware of this vulnerability and [truncated]

HIGH OpenSIPS CVE published 2026-08-04

CVE-2026-45103

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a vulnerability in versions prior to 3.6.6 and 4.0.0-rc1. The TCP message framing layer improperly parses the Content-Length header using unsigned int arithmetic with no overflow check. An attacker can send a Content-Length value that overflows unsigned int (e.g., 4294967296), causing the framing layer to compute a wrapped-around val [truncated]

CRITICAL OpenSIPS CVE published 2026-08-04

CVE-2026-45100

The OpenSIPS server implementation has a buffer overflow vulnerability in the {s.b64encode} string transformation. This issue arises from insufficient size checks, allowing an attacker to overflow the buffer by sending a SIP message with a large header value. The vulnerability affects OpenSIPS versions 3.4.0-beta through 3.6.5 and 4.0.0-beta. A remote attacker can trigger this by sending a SIP message wit [truncated]

CRITICAL OpenSIPS CVE published 2026-08-04

CVE-2026-45538

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, contains a stack buffer overflow vulnerability in versions 4.0.0 and prior. The vulnerability occurs in the sip_to_json() function when processing SIP messages with header names longer than 255 bytes. This can lead to potential remote code execution, especially in deployments where routing scripts invoke sip_to_json(). OpenSIPS users and [truncated]

HIGH OpenSIPS CVE published 2026-02-25

CVE-2026-25554

CVE-2026-25554 is a SQL injection vulnerability in OpenSIPS versions 3.1 before 3.6.4. The auth_jwt module is affected when db_mode is enabled and a SQL database backend is used. The vulnerability allows an attacker to manipulate the query result and bypass JWT authentication, enabling impersonation of arbitrary identities. This could lead to unauthorized access and potential data breaches. OpenSIPS users [truncated]