Out-of-Bounds Read Vulnerability in Kamailio SIP Signaling Server
CVE-2026-39864

4.4MEDIUM

Key Information:

Vendor

Kamailio

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-39864?

An out-of-bounds read vulnerability exists in the auth module of Kamailio SIP Signaling Server, leading to potential denial of service. This occurs when attackers send specially crafted SIP packets, causing the server to crash if the user authentication process is followed by additional identity checks without a database backend. The issue affects Kamailio versions prior to 6.0.5 and 5.8.7 and has been effectively resolved in these updates.

Affected Version(s)

kamailio < 5.8.7 < 5.8.7

kamailio >= 6.0.0, < 6.0.5 < 6.0.0, 6.0.5

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.