PT-2026-67893 · Opensips · Opensis

CVE-2026-45705

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSIPS versions prior to 3.6.6 OpenSIPS versions prior to 4.0.0-rc1
Description The find line delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. This occurs when a Session Initiation Protocol (SIP) message uses Content-Type: multipart/mixed with a boundary parameter, and the body contains a -- pattern within two to three bytes of the end without the actual boundary delimiter following it. In such cases, the function compares delimiter.len bytes starting from a position at or beyond the logical end of the body buffer, reading past the boundary.
Recommendations Update to version 3.6.6. Update to version 4.0.0-rc1.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45705
GHSA-CHXF-9368-FQCP

Affected Products

Opensis