CVE-2026-90779
SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
| CWE | CWE-121 |
| Vendor | sipp |
| Product | sipp |
| Published | Sep 13, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for sipp sipp
Be the first to know when new high vulnerabilities affecting sipp sipp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
SIPp / sipp
0 โค 3.7.7
References
github.com: https://github.com/SIPp/sipp/pull/880 github.com: https://github.com/SIPp/sipp/commit/1d4a5622bea34d0b5cdff333e6b5734608e30af7 github.com: https://github.com/SIPp/sipp/blob/v3.7.7/src/auth.cpp#L183-L192 github.com: https://github.com/SIPp/sipp vulncheck.com: https://www.vulncheck.com/advisories/sipp-through-3.7.7-stack-buffer-overflow-via-createauthheader-algorithm-parameter
Credits
๐ Tristan Madani