What is CVE-2026-45538?
CVE-2026-45538 affects OpenSIPS SIP server versions 4.0.0 and prior, where processing a SIP message with a header name longer than 255 bytes triggers a stack buffer overflow when sip_to_json() is called in the routing script. This can lead to denial of service or potential remote code execution. Users should upgrade to the latest stable version.
Azərbaycanca: CVE-2026-45538 OpenSIPS SIP server-in 4.0.0 və əvvəlki versiyalarında, 255 baytdan uzun başlıq adı olan SIP mesajını emal edərkən routing script-də sip_to_json() çağırıldıqda stack buffer overflow yaranır. Bu, təcavüzkarın xüsusi hazırlanmış paketlərlə sistemi çökdürməsinə və ya uzaqdan kod icrasına səbəb ola bilər. OpenSIPS-i ən son stabit versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
Under what condition does CVE-2026-45538 vulnerability occur?
This vulnerability occurs in OpenSIPS SIP server when a SIP message with a header name longer than 255 bytes is processed and the sip_to_json() function is called in the routing script, resulting in a stack buffer overflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.