Back Redpacketsecurity CVE Alert: CVE-2026-90778 – SIPp
SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
High availability risk for any network-reachable deployment, but the supplied data does not confirm KEV listing, active SSVC exploitation, PoC availability or EPSS probability; urgency is therefore highest for internet-facing systems.
A remotely crafted SIP request can terminate the process without authentication or user involvement, disrupting call-generation, protocol-testing or monitoring workflows. Repeated exploitation could exhaust service capacity or interrupt VoIP validation and operational activities, although the stated impact does not indicate direct data disclosure or modification.
### Most likely attack path
An attacker sends a malicious SIP message over the network, requiring low effort, no privileges and no interaction. The vulnerable parser processes an excessively long header parameter and crashes; Scope is unchanged, so direct lateral movement is not implied, but the affected host could still be used to disrupt adjacent testing or signalling operations.
### Who is most exposed
Prioritise internet-facing SIPp instances, lab services exposed for remote testing, CI/CD runners, and systems connected to production telephony or SBC environments. Privately isolated test harnesses are less exposed unless untrusted SIP traffic can reach them.
SIP and SBC logs for unusually large `To` header tags.
Alert on repeated parser errors, abnormal child-process exits or rapid service restarts.
Correlate crash times with unsolicited SIP traffic and single-source bursts.
Monitor external scanning or malformed-message patterns targeting SIP listener ports.
### Mitigation and prioritisation
Patch promptly to the vendor-maintained fixed release; confirm the deployed binary, not only package metadata.
Until patched, restrict listener access to trusted test networks using firewalls or an SBC.
Apply SIP message-size and header-length limits upstream where supported.
Run the service with least privilege and automatic restart containment.
Confirm KEV, SSVC, EPSS and PoC status before final queue placement; these indicators are currently missing.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
