Description
SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
Published: 2026-09-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (process crash)
Action: Patch Immediately
AI Analysis

Impact

SIPp versions up to 3.7.7 contain a buffer overflow in the get_peer_tag() function when parsing SIP To headers whose tag parameters are 2049 bytes or longer. This overflow does not grant code execution but triggers a crash of the SIPp process, resulting in service interruption. The flaw is a classic CWE-120 "Buffer Copy without Length Checks" vulnerability.

Affected Systems

Vulnerable versions include SIPp 3.7.7 and all earlier releases. The offending code resides in the official SIPp distribution and is fixed in subsequent releases.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can remotely trigger the overflow by sending a SIP message with an oversized tag parameter to the SIP interface used by SIPp. No elevated privileges or special configuration are required, so the risk of denial‑of‑service attacks remains significant for unpatched deployments.

Generated by OpenCVE AI on September 15, 2026 at 16:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a SIPp release newer than 3.7.7 to apply the buffer overflow fix.
  • If an immediate upgrade is not feasible, apply the patch from commit ddf22d1a54e0396b2e18ebaf4cf5a3fa860e5da4, rebuild, and redeploy.
  • Configure SIPp or the upstream firewall to reject To header tag parameters longer than 2048 bytes to prevent the overflow from being triggered during parsing.

Generated by OpenCVE AI on September 15, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Sipp
Sipp sipp
Vendors & Products Sipp
Sipp sipp

Sun, 13 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
Title SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:58.116Z

Reserved: 2026-09-13T11:15:50.569Z

Link: CVE-2026-90778

cve-icon Vulnrichment

Updated: 2026-09-14T17:06:11.895Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T12:17:16.837

Modified: 2026-09-23T17:17:47.527

Link: CVE-2026-90778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')