HIGH

CVE-2026-90779

2026-09-13 CVSS v3.1
CVSS
7.5

Description

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

Weakness (CWE)

CWE-121 Stack-based Buffer Overflow

EPSS Score

0.57%
Probability of exploitation in next 30 days
45.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE