CVE-2026-46334

OpenSIPS · opensips

OpenSIPS contains input validation and NULL pointer dereference vulnerabilities that allow unauthenticated remote attackers to crash the SIP server.

Executive summary

OpenSIPS is vulnerable to remote denial of service attacks due to improper input validation and NULL pointer dereference flaws, requiring immediate patching.

Vulnerability

The software suffers from improper input validation (CWE-20) and NULL pointer dereference (CWE-476). An unauthenticated remote attacker can send malicious SIP traffic to trigger these conditions, leading to an application crash.

Business impact

A successful exploit results in a denial of service, rendering the SIP server unable to process voice or messaging traffic. With a CVSS score of 8.7, this represents a significant risk to communications infrastructure and business-critical telephony services.

Remediation

Immediate Action: Upgrade to OpenSIPS version 3.6.6, 4.0.0-rc1, or later to address the underlying code defects.

Proactive Monitoring: Monitor SIP server logs and process status to identify unexpected service restarts or crash reports that may indicate exploitation attempts.

Compensating Controls: Use an intrusion detection system (IDS) configured to identify and drop malformed SIP packets that deviate from standard protocol specifications.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The critical nature of SIP infrastructure requires that this update be treated with high priority. Organizations should apply the provided patches immediately to restore system stability and protect against potential denial of service attacks.