PT-2026-67894 · Opensips · Opensis

CVE-2026-45809

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenSIPS versions prior to 3.6.6 OpenSIPS versions prior to 4.0.0-rc1
Description A denial of service issue exists in the watcherinfo generation functionality. A remote attacker can crash an OpenSIPS worker by sending a SUBSCRIBE Event: presence request containing a long From URI to create an oversized watcher entry, and subsequently triggering the presence.winfo watcherinfo XML generation for the same presentity. The crash occurs because the software copies the stored watcher URI into a fixed-size stack buffer, leading to a buffer overflow. This issue is configuration-dependent, requiring the presence and presence xml modules to be loaded and the handle subscribe() function to be exposed and reachable via SUBSCRIBE routing.
Recommendations Update to version 3.6.6. Update to version 4.0.0-rc1. As a temporary mitigation, restrict access to the handle subscribe() function or avoid loading the presence and presence xml modules if they are not required.

Exploit

Fix

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45809
GHSA-GX83-2GH8-7V56

Affected Products

Opensis