PT-2026-67865 · Opensips · Opensis

CVE-2026-45084

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenSIPS versions 3.4.0 through 3.6.5
Description A denial of service issue exists in the presence module of this Session Initiation Protocol (SIP) server. When the handle publish() function processes a SIP PUBLISH request containing an Event: presence header and a message body while the enable sphere check=1 configuration option is active, it calls the get content type() macro without previously executing parse content type hdr(). This sequence leads to the dereferencing of an uninitialized or NULL Content-Type parsing state, resulting in a system crash. Specifically, if the Content-Type header is present but unparsed, msg->content type->parsed is NULL; if the header is missing entirely, msg->content type is NULL. A remote attacker can trigger this crash via a single PUBLISH request over UDP or TCP. The vulnerable code path does not enforce authentication.
Recommendations Update to version 3.6.6 or 4.0.0-rc1. As a temporary mitigation, set the enable sphere check configuration option to 0.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45084
GHSA-H3WW-HCHH-X2G9

Affected Products

Opensis