CVE-2026-77322
### Summary The WebSocket transport allocates a buffer from the frame payload length before validating its size, which can lead to an unauthenticated DoS. ### Details `WSConnection.Read` allocates a buffer from the declared WebSocket frame length before reading the payload (https://github.com/emiago/sipgo/blob/v1.4.0/sip/transport_ws.go#L400): ```go data := make([]byte, header.Length) // header.Length is client-controlled, up to 2^63-1 (int64) ``` - `NextFrame()` reads only the frame header and never checks the length: `wsutil.NewReader` is created with no [`MaxFrameSize`](https://pkg.go.dev/github.com/gobwas/[email protected]/wsutil#Reader.MaxFrameSize) (`0` = unlimited). `ParseMaxMessageLength` applies only downstream, not here. - A value above the max slice size (e.g. `2^63-1`) panics `make`. sipgo does not recover from this panic, so it crashes the whole server process. ### PoC Tested on emiago/sipgo v1.4.0 (latest). After a normal WebSocket handshake, send one masked text frame consisting of the header only (no payload), declaring a huge length. The allocation runs as soon as the header is read. ``` 0x81 FIN + text opcode 0xFF MASK bit + length marker 127 (8-byte length follows) 0x7F FF FF FF FF FF FF FF declared length = 2^63-1 -> make panics (crash) <4-byte masking key> (no payload) ``` This crashes the server process: ``` panic: runtime error: makeslice: len out of range goroutine 23 [running]: github.com/emiago/sipgo/sip.(*WSConnection).Read(...) /path/to/pkg/mod/github.com/emiago/[email protected]/sip/transport_ws.go:400 +0x2df github.com/emiago/sipgo/sip.(*TransportWS).readConnection(...) /path/to/pkg/mod/github.com/emiago/[email protected]/sip/transport_ws.go:194 +0x266 created by github.com/emiago/sipgo/sip.(*TransportWS).initConnection in goroutine 21 /path/to/pkg/mod/github.com/emiago/[email protected]/sip/transport_ws.go:167 +
Properties
- ghsa_id
- GHSA-8h6x-h86x-75wh
- summary
- SIPGO: DoS via unvalidated WebSocket frame length
- severity
- high
- cvss_score
- 7.5
- cve_id
- CVE-2026-77322
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-09-23T04:35:57+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-22T20:34:30Z
- source_url
- https://github.com/advisories/GHSA-8h6x-h86x-75wh
- ghsa_updated
- 2026-09-22T20:34:31Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph