highCVSS 7.5Vulnerability

CVE-2026-77322

### Summary The WebSocket transport allocates a buffer from the frame payload length before validating its size, which can lead to an unauthenticated DoS. ### Details `WSConnection.Read` allocates a buffer from the declared WebSocket frame length before reading the payload (https://github.com/emiago/sipgo/blob/v1.4.0/sip/transport_ws.go#L400): ```go data := make([]byte, header.Length) // header.Length is client-controlled, up to 2^63-1 (int64) ``` - `NextFrame()` reads only the frame header and never checks the length: `wsutil.NewReader` is created with no [`MaxFrameSize`](https://pkg.go.dev/github.com/gobwas/[email protected]/wsutil#Reader.MaxFrameSize) (`0` = unlimited). `ParseMaxMessageLength` applies only downstream, not here. - A value above the max slice size (e.g. `2^63-1`) panics `make`. sipgo does not recover from this panic, so it crashes the whole server process. ### PoC Tested on emiago/sipgo v1.4.0 (latest). After a normal WebSocket handshake, send one masked text frame consisting of the header only (no payload), declaring a huge length. The allocation runs as soon as the header is read. ``` 0x81 FIN + text opcode 0xFF MASK bit + length marker 127 (8-byte length follows) 0x7F FF FF FF FF FF FF FF declared length = 2^63-1 -> make panics (crash) <4-byte masking key> (no payload) ``` This crashes the server process: ``` panic: runtime error: makeslice: len out of range goroutine 23 [running]: github.com/emiago/sipgo/sip.(*WSConnection).Read(...) /path/to/pkg/mod/github.com/emiago/[email protected]/sip/transport_ws.go:400 +0x2df github.com/emiago/sipgo/sip.(*TransportWS).readConnection(...) /path/to/pkg/mod/github.com/emiago/[email protected]/sip/transport_ws.go:194 +0x266 created by github.com/emiago/sipgo/sip.(*TransportWS).initConnection in goroutine 21 /path/to/pkg/mod/github.com/emiago/[email protected]/sip/transport_ws.go:167 +

Properties

ghsa_id
GHSA-8h6x-h86x-75wh
summary
SIPGO: DoS via unvalidated WebSocket frame length
severity
high
cvss_score
7.5
cve_id
CVE-2026-77322
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-23T04:35:57+00:00
is_ghsa_only
false
ghsa_published
2026-09-22T20:34:30Z
source_url
https://github.com/advisories/GHSA-8h6x-h86x-75wh
ghsa_updated
2026-09-22T20:34:31Z

Related Entities (4)

AFFECTS (1)

[Software]go/github.com/emiago/sipgo

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/emiago/sipgo

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77322 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal