CVE-2026-46334 Details
Description
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.
A denial-of-service vulnerability has been identified in OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1. The issue arises in the Session Description Protocol (SDP) bandwidth-line parsing logic. When a SIP request with 'Content-Type: application/sdp' includes a malformed session-level SDP bandwidth line that lacks the necessary colon delimiter, it can corrupt the parsed SDP bandwidth metadata. This corruption leads to a crash when the flawed SDP state is cloned by routing scripts or modules that handle dialogs and Quality of Service (QoS) processing. An unauthenticated remote attacker can exploit this vulnerability to cause a crash in any configuration that processes attacker-controlled SDP and applies dialog or QoS management.
Users are advised to upgrade to OpenSIPS versions 3.6.6, 4.0.0-rc1, or later fixed releases. If an immediate upgrade is not feasible, access to the affected feature should be restricted or disabled until the patch can be applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |