Stack Buffer Overflow in sngrep SIP Packet Processing by Irontec
CVE-2026-90558

9.3CRITICAL

Key Information:

Vendor

Irontec

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90558?

The sngrep application, up to version 1.8.4, contains a stack buffer overflow vulnerability due to improper handling of SIP headers that exceed the 255-byte limit. Attackers can exploit this flaw by sending specially crafted SIP packets with oversized Call-ID or X-Call-ID headers. The resulting stack overflow may lead to crashes or the execution of arbitrary code during the processing of these packets, posing significant security risks to systems using this application.

Affected Version(s)

sngrep 0 <= 1.8.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.