Skip to content
Critical Buffer Overflow Vulnerability in OpenSIPS (CVE-2026-45537)

Critical Buffer Overflow Vulnerability in OpenSIPS (CVE-2026-45537)

First seen 1 Oct 2026, 07:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 07:03 UTC
  • •CVE-2026-45537 is a critical buffer overflow in OpenSIPS affecting versions before 3.6.6.
  • •Attackers can exploit this flaw by sending crafted SIP messages with long usernames.
  • •The vulnerability has been patched in OpenSIPS versions 3.6.6 and 4.0.0-rc1.

CVE-2026-45537 is a critical buffer overflow vulnerability in OpenSIPS, an open-source SIP server, allowing remote unauthenticated attackers to corrupt global data and alter routing behavior. The flaw exists in the construct_uri() function, which lacks bounds checking when concatenating URI components into a fixed 1024-byte buffer. Attackers can exploit this vulnerability by sending SIP messages with long usernames, affecting OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1. The vulnerability has a CVSS score of 9.1, indicating its critical nature. The issue has been fixed in the mentioned versions, and users are urged to update their systems. Without proper mitigation, the vulnerability can undermine the integrity and availability of OpenSIPS deployments. The vulnerability was published on August 4, 2026, and has been included in the NVD database.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-04
CVE-2026-45537 published
CVE-2026-45537 was published to the NVD, detailing a critical buffer overflow in OpenSIPS.
www.sentinelone.com
2026-08-05
NVD database updated
The NVD database was last updated with information on CVE-2026-45537.
www.sentinelone.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-45537 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which OpenSIPS versions are affected?
OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1 are affected by CVE-2026-45537.
What is the impact of this vulnerability?
Attackers can exploit this vulnerability to corrupt global server state and alter SIP routing behavior.
How can I mitigate this vulnerability?
Update to OpenSIPS versions 3.6.6 or 4.0.0-rc1 to mitigate the vulnerability.