PT-2026-97039 · Sipgo · Sipgo
CVE-2026-77322
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SIPGO versions prior to 1.4.3
Description
An unauthenticated WS or WSS peer can cause a denial of service in the server process. The issue occurs because
WSConnection.Read in sip/transport ws.go creates a wsutil.Reader without setting MaxFrameSize, which allows NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An attacker can send a frame header declaring an extremely large payload, leading to an oversized memory allocation or a makeslice length panic, resulting in a server crash or memory exhaustion.Recommendations
Update SIPGO to version 1.4.3.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sipgo