Description
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
Published: 2026-09-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

SIPp through version 3.7.7 includes a stack buffer overflow in the createAuthHeader() routine that is triggered when processing SIP authentication challenges with oversized algorithm parameters. The vulnerability can be exercised by a malicious SIP server sending a crafted 401 or 407 challenge. The overflow corrupts the client’s stack and leads to a crash, resulting in a denial‑of‑service outcome.

Affected Systems

The affected product is SIPp, the open‑source SIP testing tool. All releases up to and including version 3.7.7 are vulnerable; newer releases patch the issue.

Risk and Exploitability

The CVSS score is 8.7, indicating a severe vulnerability. The EPSS score is < 1%, and the CVE is not listed in the CISA KEV catalogue, so the exact exploitation likelihood is unknown, but the vulnerability can be triggered by any SIP server that the client communicates with. An attacker with network visibility can send a crafted challenge to a vulnerable SIPp client to force a crash and disrupt service.

Generated by OpenCVE AI on September 15, 2026 at 16:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SIPp to version 3.7.8 or later, which includes the patch for the buffer overflow.
  • Configure SIPp or upstream devices to reject authentication challenges whose algorithm parameter length exceeds the normal maximum, preventing oversized values from reaching the application.
  • Deploy network monitoring or IDS/IPS rules to detect and block SIP 401/407 messages that violate RFC 3261 by containing unusually long algorithm fields, and configure the service to automatically restart if it crashes to reduce downtime.

Generated by OpenCVE AI on September 15, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Sipp
Sipp sipp
Vendors & Products Sipp
Sipp sipp

Sun, 13 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
Title SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:59.067Z

Reserved: 2026-09-13T11:15:54.633Z

Link: CVE-2026-90779

cve-icon Vulnrichment

Updated: 2026-09-14T15:34:17.891Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T12:17:16.960

Modified: 2026-09-23T17:17:44.380

Link: CVE-2026-90779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow