


Perceptive Security
SOC/SIEM Consultancy

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 …
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 22:03:03
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
CVE-2026-45538 is an unpatched stack buffer overflow vulnerability in OpenSIPS versions 4.0.0 and prior. The vulnerability exists in the sip_to_json() function within modules/sipmsgops/sipmsgops.c, which copies SIP header names into a fixed 255-byte stack buffer without bounds checking. An attacker can craft a SIP message with a header name exceeding 255 bytes (up to ~65000 bytes) to trigger the overflow. The vulnerability is exploitable via a single unauthenticated UDP packet sent to the SIP port (5060). Exploitation can result in process crash or, on builds lacking stack protections, full remote code execution through return address hijacking. Both the length and content of the stack overwrite are attacker-controlled, making this a highly severe issue. Only deployments whose routing scripts invoke sip_to_json() are affected. No fix was available at the time of publication.
Technical details
Mitigation steps:
Affected products:
OpenSIPS 4.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45538
https://github.com/OpenSIPS/opensips/security/advisories/GHSA-37wc-5j8j-95x3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
