Buffer Overflow Vulnerability in OpenSIPS SIP Server
CVE-2026-45100

9.1CRITICAL

Key Information:

Vendor

Opensips

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-45100?

OpenSIPS, a popular Session Initiation Protocol (SIP) server, is vulnerable to a buffer overflow due to improper handling of base64 encoded data in the {s.b64encode} string transformation. This vulnerability primarily affects versions 3.4.0-beta through 3.6.5 and 4.0.0-beta. The issue arises from a lack of sufficient size checks for input data, allowing a remote attacker to exploit this weakness by sending a SIP message with oversized headers. If the input size exceeds the limits during base64 encoding, it can overflow adjacent memory buffers, leading to potential manipulation of subsequent transformation processes. The vulnerability has been addressed in versions 3.6.6 and 4.0.0-rc1, and it is essential for users to upgrade their installations to mitigate the risk.

Affected Version(s)

opensips >= 3.4.0-beta, < 3.6.6 < 3.4.0-beta, 3.6.6

opensips >= 4.0.0-beta, < 4.0.0-rc1 < 4.0.0-beta, 4.0.0-rc1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.