HIGHVulnerability

CVE-2026-90778

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-90778
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-13T12:17:16.837
last_modified
2026-09-23T17:17:47.527

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90778 — Ninja Signal Threat Intelligence | Ninja Signal