What is CVE-2026-45537?
A buffer overflow vulnerability has been identified in the construct_uri() function of the OpenSIPS SIP server, affecting versions prior to 3.6.6 and 4.0.0-rc1. This occurs when URI components are concatenated into a fixed 1024-byte global BSS buffer without bounds checking. Upgrading OpenSIPS to the latest version is recommended.
Azərbaycanca: OpenSIPS SIP server-inin construct_uri() funksiyasında 3.6.6 və 4.0.0-rc1 versiyalarından əvvəlki versiyalara təsir edən buffer overflow zəifliyi aşkar edilib. Bu zəiflik URI komponentlərinin heç bir yoxlama olmadan 1024 baytlıq global BSS buffer-ə birləşdirilməsi nəticəsində yaranır. OpenSIPS-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: OpenSIPS
FAQ2
In which function of OpenSIPS was CVE-2026-45537 discovered?
The vulnerability was discovered in the construct_uri() function of the OpenSIPS SIP server.
How does this buffer overflow vulnerability occur?
This vulnerability occurs when URI components are concatenated into a fixed 1024-byte global BSS buffer without bounds checking.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.