Skip to content
Critical Buffer Overflow Vulnerabilities in SIPp Discovered

Critical Buffer Overflow Vulnerabilities in SIPp Discovered

First seen 13 Sep 2026, 20:43 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 20:44 UTC
  • CVE-2026-90778 and CVE-2026-90779 affect SIPp versions up to 3.7.7.
  • Both vulnerabilities allow unauthenticated remote exploitation, leading to process crashes.
  • Immediate patching and access restrictions are critical for internet-facing deployments.

Two critical vulnerabilities, CVE-2026-90778 and CVE-2026-90779, have been identified in SIPp versions up to 3.7.7. CVE-2026-90778 allows unauthenticated remote attackers to exploit a buffer overflow in the get_peer_tag() function, while CVE-2026-90779 affects the createAuthHeader() function, leading to stack corruption. Both vulnerabilities can cause the SIPp process to crash, disrupting call generation and monitoring workflows. The vulnerabilities are particularly dangerous for internet-facing deployments, where attackers can send crafted SIP messages to exploit the flaws without requiring authentication or user interaction. No proof-of-concept code or active exploitation has been confirmed yet, but the urgency for remediation is high. Affected systems include automated SIP test harnesses and monitoring systems connected to untrusted endpoints. Immediate patching and access restrictions are recommended for vulnerable systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-13
CVE-2026-90778 published
Buffer overflow vulnerability in SIPp's get_peer_tag() function disclosed, affecting versions up to 3.7.7.
Redpacketsecurity
2026-09-13
CVE-2026-90779 published
Stack buffer overflow vulnerability in createAuthHeader() function disclosed, affecting versions up to 3.7.7.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-90778 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed