What is CVE-2026-45809?
A denial of service vulnerability exists in the watcherinfo generation of OpenSIPS SIP server prior to versions 3.6.6 and 4.0.0-rc1. Attackers can create an oversized watcher entry via a crafted SUBSCRIBE Event: presence request, potentially causing service disruption. Users are advised to update to the latest patched versions immediately.
Azərbaycanca: OpenSIPS SIP server-in 3.6.6 və 4.0.0-rc1 öncəsi versiyalarında 'watcherinfo' yaradılmasında denial of service zəifliyi aşkarlanıb. Təcavüzkar xüsusi hazırlanmış SUBSCRIBE sorğusu ilə həddən artıq böyük 'watcher' qeydi yaradaraq servisi sıradan çıxara bilər. İstifadəçilərə dərhal versiyalarını yeniləmələri tövsiyə olunur.
FAQ2
Which versions of OpenSIPS are affected by CVE-2026-45809?
OpenSIPS SIP server versions prior to 3.6.6 and 4.0.0-rc1 are affected.
How can the CVE-2026-45809 vulnerability be exploited?
An attacker can trigger a denial of service (DoS) by creating an oversized 'watcher' entry via a crafted SUBSCRIBE request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.