PT-2026-67894 · Opensips · Opensis
CVE-2026-45809
·
Published
2026-08-04
·
Updated
2026-08-05
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenSIPS versions prior to 3.6.6
OpenSIPS versions prior to 4.0.0-rc1
Description
A denial of service issue exists in the watcherinfo generation functionality. A remote attacker can crash an OpenSIPS worker by sending a SUBSCRIBE Event: presence request containing a long From URI to create an oversized watcher entry, and subsequently triggering the
presence.winfo watcherinfo XML generation for the same presentity. The crash occurs because the software copies the stored watcher URI into a fixed-size stack buffer, leading to a buffer overflow. This issue is configuration-dependent, requiring the presence and presence xml modules to be loaded and the handle subscribe() function to be exposed and reachable via SUBSCRIBE routing.Recommendations
Update to version 3.6.6.
Update to version 4.0.0-rc1.
As a temporary mitigation, restrict access to the
handle subscribe() function or avoid loading the presence and presence xml modules if they are not required.Exploit
Fix
DoS
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensis