What is CVE-2026-45705?
CVE-2026-45705: In OpenSIPS SIP server versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. This vulnerability may lead to remote code execution or denial of service. Immediate update to versions 3.6.6 or 4.0.0-rc1 is strongly recommended.
Azərbaycanca: CVE-2026-45705: OpenSIPS SIP server-inin 3.6.6 və 4.0.0-rc1 versiyalarından əvvəlki versiyalarında, multipart body parser-də find_line_delimiter() funksiyası MIME boundary delimiter-lərini axtararkən strncmp() vasitəsilə out-of-bounds read zəifliyinə səbəb olur. Bu zəiflik uzaqdan kod icrasına və ya xidmətin dayandırılmasına (DoS) yol aça bilər. İstifadəçilərə təcili olaraq 3.6.6 və ya 4.0.0-rc1 versiyalarına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of OpenSIPS are affected by CVE-2026-45705?
This vulnerability affects OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1.
How can one protect against CVE-2026-45705?
Immediate update to versions 3.6.6 or 4.0.0-rc1 is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.