


Perceptive Security
SOC/SIEM Consultancy

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Conten…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 23:03:20
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
OpenSIPS SIP server versions prior to 3.6.6 and 4.0.0-rc1 contain an integer overflow vulnerability in the TCP message framing layer. The Content-Length header is parsed using unsigned int arithmetic without overflow checks, allowing attackers to send crafted values (e.g., 4294967296) that wrap around to zero, causing incorrect TCP stream splitting. This enables SIP message smuggling over any TCP-based transport including proto_tcp, proto_tls, proto_ws, and proto_wss. Since the parsing occurs before authentication, unauthenticated remote attackers can exploit this with no preconditions. Successful exploitation allows bypassing SBC/proxy security policies, inheriting connection authentication context, and evading rate limiting. Patches are available in versions 3.6.6 and 4.0.0-rc1.
Technical details
Mitigation steps:
Affected products:
OpenSIPS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45103
https://github.com/OpenSIPS/opensips/commit/4d23613b
https://github.com/OpenSIPS/opensips/commit/5f103eff
https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jv35-555v-54jh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
