PT-2026-97019 · Sipgo · Sipgo

CVE-2026-58268

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SIPGO versions prior to 1.4.1
Description An unauthenticated peer can cause a denial of service by sending a stream-transport message over TCP, TLS, WS, or WSS with an oversized declared length. The ParserStream.parseSingle() function in sip/parser stream.go allocates a SIP body buffer based on the client-controlled Content-Length header before the ParseMaxMessageLength limit is enforced. This allows an attacker to trigger excessive memory allocation before the message body is actually read.
Recommendations Update to version 1.4.1.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58268
GHSA-PG59-5VWG-4JXQ

Affected Products

Sipgo