What is CVE-2026-45103?
CVE-2026-45103: A vulnerability in OpenSIPS SIP server versions prior to 3.6.6 allows attackers to trigger an unsigned integer overflow via a crafted Content-Length header in the TCP message framing layer. This could lead to potential denial of service. Users should upgrade to version 3.6.6 or 4.0.0-rc1.
Azərbaycanca: CVE-2026-45103: OpenSIPS SIP server-in 3.6.6-dan əvvəlki versiyalarında TCP message framing qatında Content-Length başlığının unsigned int ilə yoxlanılmaması səbəbindən overflow zəifliyi aşkarlanıb. Bu, uzaqdan hücumçulara serverin işini pozmağa imkan verə bilər. İstifadəçilərə 3.6.6 və ya 4.0.0-rc1 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which versions of OpenSIPS are affected by CVE-2026-45103?
The vulnerability affects OpenSIPS versions prior to 3.6.6.
What is the potential impact of this vulnerability?
This vulnerability could allow remote attackers to cause a denial of service (DoS), disrupting the server's operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.