HIGHVulnerability

CVE-2026-90780

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-90780
signal_observed_at
2026-09-23T04:35:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-13T12:17:17.093
last_modified
2026-09-20T01:16:32.707

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90780 — Ninja Signal Threat Intelligence | Ninja Signal