THREAT OPS › Threat News › [NVD] CVE-2026-90778 (HIGH 7.5) — SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buf
[NVD] CVE-2026-90778 (HIGH 7.5) — SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buf
CVE-2026-90778 CVSS: 7.5 HIGH Published: 2026-09-13T12:17:16.837
SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
Indicators of compromise
- CVE-2026-90778cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90778