OpenSIPS vulnerabilities
4 CVEs tracked
In the current reporting period, the OpenSIPS SIP server is prominent due to several critical vulnerabilities. Key themes include denial of service (DoS) attacks via the 'presence' module through malformed SIP requests (CVE-2026-45084, CVE-2026-45809) and critical buffer overflow issues (CVE-2026-45100, CVE-2026-45537) affecting versions from 3.4.0-beta through 3.6.5 and 4.0.0-beta. Defenders must prioritize applying the recommended security patches for these CVEs and enhance monitoring of SIP PUBLISH and SUBSCRIBE requests, especially on exposed network interfaces.
Azərbaycanca: Hesabat dövründə OpenSIPS SIP serveri təhlükəsizlik kontekstində bir neçə kritik zəiflik səbəbilə önə çıxır. Əsas mövzular arasında xüsusi hazırlanmış SIP sorğuları vasitəsilə xidmət dayandırma (DoS) hücumlarına səbəb olan "presence" modulu zəiflikləri (CVE-2026-45084, CVE-2026-45809) və məhsulun 3.4.0-beta-dan 3.6.5-ə qədər, həmçinin 4.0.0-beta versiyalarını təsir edən kritik buffer overflow problemləri (CVE-2026-45100, CVE-2026-45537) üstünlük təşkil edir. Müdafiəçilər bu CVE-lər üçün təklif olunan təhlükəsizlik yamalarını dərhal tətbiq etməyə, xüsusilə də açıq şəbəkə interfeyslərində SIP PUBLISH, SUBSCRIBE sorğularının monitorinqini gücləndirməyə diqqət etməlidirlər.
This vendor's CVEs4
This hub is built from skopnix's own reporting on OpenSIPS: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.