PT-2026-97039 · Sipgo · Sipgo

CVE-2026-77322

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SIPGO versions prior to 1.4.3
Description An unauthenticated WS or WSS peer can cause a denial of service in the server process. The issue occurs because WSConnection.Read in sip/transport ws.go creates a wsutil.Reader without setting MaxFrameSize, which allows NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An attacker can send a frame header declaring an extremely large payload, leading to an oversized memory allocation or a makeslice length panic, resulting in a server crash or memory exhaustion.
Recommendations Update SIPGO to version 1.4.3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77322
GHSA-8H6X-H86X-75WH

Affected Products

Sipgo