PT-2026-31443 · Kamailio · Kamailio

CVE-2026-39864

·

Published

2026-04-08

·

Updated

2026-04-08

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kamailio versions prior to 6.0.5 and 5.8.7
Description Kamailio, an open source SIP Signaling Server, contains a flaw in the auth module. A specially crafted SIP packet can trigger an out-of-bounds read, leading to a denial of service (process crash) if a successful user authentication occurs without a database backend, followed by further user identity checks.
Recommendations Update to version 6.0.5 or 5.8.7

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39864
GHSA-6M86-M342-G48M

Affected Products

Kamailio