Denial of Service Vulnerability in OpenSIPS SIP Server by OpenSIPS
CVE-2026-45809

8.7HIGH

Key Information:

Vendor

Opensips

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-45809?

An issue in the OpenSIPS SIP server implementation allows remote attackers to cause a denial of service via oversized watcher entries. By sending a SUBSCRIBE Event: presence request with a lengthy From URI, attackers can trigger an overflow in the presence.winfo watcherinfo XML generation process, leading to the crash of an OpenSIPS worker process. This vulnerability is contingent on specific configurations, as the presence and presence_xml modules must be active, and the routing of SUBSCRIBE requests must be accessible. The flaw has been addressed in the releases 3.6.6 and 4.0.0-rc1.

Affected Version(s)

opensips >= 3.4.0, < 3.6.6 < 3.4.0, 3.6.6

opensips >= 4.0.0-beta, < 4.0.0-rc1 < 4.0.0-beta, 4.0.0-rc1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.