๐Ÿ” CVE Alert

CVE-2026-45809

UNKNOWN 0.0

OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a long From URI, and then trigger presence.winfo watcherinfo XML generation for the same presentity. OpenSIPS copies the stored watcher URI into a fixed-size stack buffer, overflowing it and crashing the process. A remote attacker can crash an OpenSIPS worker in deployments that expose handle_subscribe() and allow watcherinfo (presence.winfo) generation. The issue is configuration-dependent because the presence and presence_xml modules must be loaded and SUBSCRIBE routing must be reachable. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.

CWE CWE-121
Vendor opensips
Product opensips
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for opensips opensips

Be the first to know when new unknown vulnerabilities affecting opensips opensips are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenSIPS / opensips
>= 3.4.0, < 3.6.6 >= 4.0.0-beta, < 4.0.0-rc1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenSIPS/opensips/security/advisories/GHSA-gx83-2gh8-7v56 github.com: https://github.com/OpenSIPS/opensips/commit/c5970d3ee25b457ad2d78fe6e9662a12dae577cd github.com: https://github.com/OpenSIPS/opensips/commit/dd86461b71ff4a4f5194205896ae5f48f144240d