Description
SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
Published: 2026-09-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

SIPp versions up to 3.7.7 contain a buffer overflow in the get_header() routine of src/sip_parser.cpp when a SIP message contains header content larger than 20,490 bytes. The overflow corrupts a static buffer, causing the SIPp process to crash. Attackers do not need authentication and can trigger the vulnerability remotely by sending a crafted SIP message with an oversized header, leading to disruption of the application's availability.

Affected Systems

The vulnerable product is SIPp, specifically releases 3.7.7 and earlier. All installations of these versions that receive unfiltered SIP traffic are at risk.

Risk and Exploitability

The CVSS score of 8.7 signals a high‑severity flaw. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting the public is still becoming aware of it. An unauthenticated attacker can exploit this by injecting a malicious SIP request with an excessively large header; successful exploitation results in a process crash, making the application unavailable until it is restarted. The exposure is remote and does not require local or privileged access.

Generated by OpenCVE AI on September 15, 2026 at 16:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SIPp to version 3.7.8 or later to apply the buffer overflow fix.
  • If an upgrade is not possible, apply the source patch corresponding to commit 8ddfb43359703e665041a955543e07f504f80232 or merge pull request 881 to correct the header parsing loop.
  • As a temporary mitigation, configure your network or SIP proxy to reject or truncate SIP messages whose headers exceed 20,490 bytes, preventing the overflow from reaching the application.

Generated by OpenCVE AI on September 15, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Sipp
Sipp sipp
Vendors & Products Sipp
Sipp sipp

Sun, 13 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
Title SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:00.064Z

Reserved: 2026-09-13T11:15:58.849Z

Link: CVE-2026-90780

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:54.292Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T12:17:17.093

Modified: 2026-09-23T17:17:44.397

Link: CVE-2026-90780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')