What is CVE-2026-45084?
A denial of service vulnerability exists in the presence module of OpenSIPS versions 3.4.0 through 3.6.5. This can be exploited by sending a specially crafted SIP PUBLISH request with an Event: presence header to the handle_publish() function. It is recommended to update OpenSIPS to the latest stable version.
Azərbaycanca: OpenSIPS-in 3.4.0-dən 3.6.5-ə qədər versiyalarında "presence" modulunda denial of service zəifliyi aşkar edilib. "Event: presence" başlığı ilə göndərilən xüsusi SIP PUBLISH sorğuları handle_publish() funksiyasında problemin istismarına səbəb ola bilər. Təhlükəsizlik üçün OpenSIPS-i ən son stabil versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which versions of OpenSIPS are affected by this denial of service vulnerability?
The vulnerability exists in OpenSIPS versions 3.4.0 through 3.6.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.