Description
SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can send a single short RTP packet or malformed zero-to-seven-byte STUN address attribute to the shared RTP/ICE socket, including during ICE connectivity checks before DTLS or STUN MESSAGE-INTEGRITY verification, and terminate the active RTP or WebRTC media session. The attacker must reach or learn the advertised ephemeral RTP/ICE port, but no authentication or user interaction is required, and the impact is limited to availability. This issue is fixed in version 10.0.9.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Availability (Denial of Service)
Action: Patch ASAP
AI Analysis

Impact

SIPSorcery, a WebRTC, SIP, and VoIP library for C# and .NET, has an input validation flaw in the RTPChannel.OnRTPPacketReceived and the STUN attribute parsing routines. Untrusted packet data is indexed without adequate length checks, which can trigger an index‑out‑of‑bounds exception. Because UdpReceiver.EndReceiveFrom closes the channel whenever a non‑socket exception occurs, the effect is an abrupt termination of an active RTP or WebRTC media session. The attack requires only knowledge of the advertised UDP port and no authentication, limiting the impact to availability.

Affected Systems

The vulnerability is present in any version of sipsorcery before 10.0.9. Any deployment that uses the SIPSorcery library for real‑time media will be impacted if the RTP/ICE socket is exposed to unknown network participants.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity. The EPSS score is < 1%, so the likelihood of exploitation at this time is low, but the fact that no authentication is required and the attack requires only knowledge of the advertised UDP port makes it a realistic threat. The vulnerability is not currently listed CISA’s KEV catalog, so no public exploits are documented, but since attackers do not need to authenticate and only need knowledge of the advertised UDP port, this remote attack can pose a real risk if the port is reachable from the broader internet.

Generated by OpenCVE AI on September 20, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SIPSorcery to version 10.0.9 or newer, which adds proper bounds checks to RTP and STUN parsing.
  • Restrict inbound UDP traffic on the RTP/ICE port to known peers or trusted IP ranges with firewall or NAT policies, limiting exposure to arbitrary attackers.
  • Monitor logs for repeated abnormal RTP or STUN messages and investigate promptly.

Generated by OpenCVE AI on September 20, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-28gm-jrmw-xx93 SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sipsorcery-org
Sipsorcery-org sipsorcery
Vendors & Products Sipsorcery-org
Sipsorcery-org sipsorcery

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can send a single short RTP packet or malformed zero-to-seven-byte STUN address attribute to the shared RTP/ICE socket, including during ICE connectivity checks before DTLS or STUN MESSAGE-INTEGRITY verification, and terminate the active RTP or WebRTC media session. The attacker must reach or learn the advertised ephemeral RTP/ICE port, but no authentication or user interaction is required, and the impact is limited to availability. This issue is fixed in version 10.0.9.
Title SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
Weaknesses CWE-20
CWE-755
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Sipsorcery-org Sipsorcery
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:43:28.069Z

Reserved: 2026-06-15T20:07:02.185Z

Link: CVE-2026-54632

cve-icon Vulnrichment

Updated: 2026-09-15T14:43:24.887Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:47.010

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-755

    Improper Handling of Exceptional Conditions