{"id":"CVE-2026-45103","summary":"OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow","details":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be processed as a separate message and enabling SIP message smuggling. Because Content-Length is parsed in the transport layer before authentication, an unauthenticated, network-based attacker can smuggle arbitrary SIP messages over any TCP-based transport (proto_tcp, proto_tls, proto_ws, proto_wss) on any instance with TCP enabled, with no routing-script preconditions. This allows smuggled messages to bypass front-end SBC/proxy security policies, inherit the connection's authentication context, and evade rate limiting. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","aliases":["GHSA-jv35-555v-54jh"],"modified":"2026-08-12T03:51:20.191930492Z","published":"2026-08-04T21:56:57.422Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45103.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45103.json"},{"type":"ADVISORY","url":"https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jv35-555v-54jh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45103"},{"type":"FIX","url":"https://github.com/OpenSIPS/opensips/commit/4d23613b"},{"type":"FIX","url":"https://github.com/OpenSIPS/opensips/commit/5f103eff"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensips/opensips","events":[{"introduced":"f3e0d5333913bcaace4c8f8711871550accca63f"},{"introduced":"985272ff3d7ebc5e9f24ad9f8fcf8b1d2549f1b6"},{"fixed":"26c0c4e3364806e77c2915b1c3e03bf9bd90dccd"},{"fixed":"b3621031661ed10d6af511d7c41f512075357a00"},{"fixed":"4d23613b"},{"fixed":"5f103eff"}],"database_specific":{"extracted_events":[{"introduced":"3.4.0"},{"fixed":"3.6.6"},{"introduced":"4.0.0-beta"},{"fixed":"4.0.0-rc1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["4.0.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45103.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}