THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90778 (HIGH 7.5) — SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buf

[NVD] CVE-2026-90778 (HIGH 7.5) — SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buf

mednvdPublished 2026-09-13

CVE-2026-90778 CVSS: 7.5 HIGH Published: 2026-09-13T12:17:16.837

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90778