Denial of Service Vulnerability in OpenSIPS SIP Server by OpenSIPS
CVE-2026-45809
8.7HIGH
What is CVE-2026-45809?
An issue in the OpenSIPS SIP server implementation allows remote attackers to cause a denial of service via oversized watcher entries. By sending a SUBSCRIBE Event: presence request with a lengthy From URI, attackers can trigger an overflow in the presence.winfo watcherinfo XML generation process, leading to the crash of an OpenSIPS worker process. This vulnerability is contingent on specific configurations, as the presence and presence_xml modules must be active, and the routing of SUBSCRIBE requests must be accessible. The flaw has been addressed in the releases 3.6.6 and 4.0.0-rc1.
Affected Version(s)
opensips >= 3.4.0, < 3.6.6 < 3.4.0, 3.6.6
opensips >= 4.0.0-beta, < 4.0.0-rc1 < 4.0.0-beta, 4.0.0-rc1
