Out-of-Bounds Read Vulnerability in Kamailio by Kamailio Solutions
CVE-2026-82608
Key Information:
- Vendor
Kamailio Solutions
- Status
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82608?
A vulnerability affecting Kamailio versions up to 5.5.0 and 6.0.7 has been reported where an out-of-bounds read can occur due to improper handling in the get_4bytes function of the AVP Handler component. This vulnerability allows attackers to exploit the flaw remotely, potentially leading to unauthorized access or exposure of sensitive information. Given that version 5.5.0 is no longer maintained, users are advised to upgrade to newer versions and apply the patch identified as abb5d60af6eefbd367bf6588c5589566b090e272 to mitigate risks associated with this vulnerability.
Affected Version(s)
Kamailio 5.0
Kamailio 5.1
Kamailio 5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
