๐Ÿ” CVE Alert

CVE-2026-46334

UNKNOWN 0.0

OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.

CWE CWE-476 CWE-20
Vendor opensips
Product opensips
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for opensips opensips

Be the first to know when new unknown vulnerabilities affecting opensips opensips are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenSIPS / opensips
>= 3.4.0, < 3.6.6 >= 4.0.0-beta, < 4.0.0-rc1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenSIPS/opensips/security/advisories/GHSA-rh36-mhpv-cx2r github.com: https://github.com/OpenSIPS/opensips/commit/8fe74b01f6fbf86c0b5e290735275530cb65e0fb github.com: https://github.com/OpenSIPS/opensips/commit/ac5309d5b8206cd3dbe1b4e01567c8db1ce31444