LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-45537

Published
CVSS9.1
Severitycritical
WeaknessCWE-120
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component length exceeding 1024 bytes overflows the buffer, corrupting adjacent global data with attacker-controlled content. The overflow reaches disable_503_translation, a global flag controlling SIP 503 response handling, allowing an attacker to deterministically set the flag via the URI username and alter the

References

← Back to the CVE Tracker

Our coverage of CVE-2026-45537

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-45537.