Buffer Overflow Vulnerability in SIPp Product by SIPp Vendor
CVE-2026-90780

8.7HIGH

Key Information:

Vendor

Sipp

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90780?

SIPp versions up to 3.7.7 contain a buffer overflow vulnerability within the get_header() function located in src/sip_parser.cpp. This issue arises when the software processes SIP messages with header content exceeding 20,490 bytes. As a result, unauthenticated remote attackers can exploit this flaw by sending crafted SIP messages with oversized headers, leading to potential crashes of the SIPp service due to buffer overflow.

Affected Version(s)

sipp 0 <= 3.7.7

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.