CVE-2026-52022
7.5Kamailio · Kamailio
A denial of service vulnerability exists in the Kamailio IMS P-CSCF registration handling components, allowing unauthenticated remote attackers to disrupt service availability.
Executive summary
A high-severity denial of service vulnerability in Kamailio, version 6.1.1 and earlier, enables unauthenticated remote attackers to crash the IMS P-CSCF registration service.
Vulnerability
The vulnerability exists within the IMS P-CSCF registration handling components. It is an unauthenticated flaw that allows a remote attacker to trigger a denial of service condition by sending specifically crafted registration requests.
Business impact
Successful exploitation of this vulnerability results in a denial of service, which can render critical telecommunications infrastructure unavailable. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to service continuity, potentially causing substantial operational downtime and service disruption for dependent users or downstream systems.
Remediation
Immediate Action: Upgrade the Kamailio instance to a version beyond 6.1.1 that incorporates the fix provided in commit 91c5ca751799db4f25a28a495350cc97f7c2f390.
Proactive Monitoring: Monitor system logs for unusual spikes in registration requests or service instability within the P-CSCF module.
Compensating Controls: Implement rate limiting or traffic shaping at the network perimeter to restrict the volume of registration requests reaching the P-CSCF component.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Kamailio should prioritize testing and applying the upstream fix as soon as it is integrated into their specific distribution. Due to the potential for service disruption, maintaining high availability for the P-CSCF registration service is critical, and patching remains the most effective method to eliminate the vulnerability.
More Kamailio CVEs
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written
- Published in the daily brief high section, early-warning entry