{"id":"CVE-2026-45809","summary":"OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI","details":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a long From URI, and then trigger presence.winfo watcherinfo XML generation for the same presentity. OpenSIPS copies the stored watcher URI into a fixed-size stack buffer, overflowing it and crashing the process. A remote attacker can crash an OpenSIPS worker in deployments that expose handle_subscribe() and allow watcherinfo (presence.winfo) generation. The issue is configuration-dependent because the presence and presence_xml modules must be loaded and SUBSCRIBE routing must be reachable. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","aliases":["GHSA-gx83-2gh8-7v56"],"modified":"2026-08-07T21:32:31.422907Z","published":"2026-08-04T23:30:03.111Z","database_specific":{"cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45809.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45809.json"},{"type":"ADVISORY","url":"https://github.com/OpenSIPS/opensips/security/advisories/GHSA-gx83-2gh8-7v56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45809"},{"type":"FIX","url":"https://github.com/OpenSIPS/opensips/commit/c5970d3ee25b457ad2d78fe6e9662a12dae577cd"},{"type":"FIX","url":"https://github.com/OpenSIPS/opensips/commit/dd86461b71ff4a4f5194205896ae5f48f144240d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensips/opensips","events":[{"introduced":"f3e0d5333913bcaace4c8f8711871550accca63f"},{"introduced":"985272ff3d7ebc5e9f24ad9f8fcf8b1d2549f1b6"},{"fixed":"26c0c4e3364806e77c2915b1c3e03bf9bd90dccd"},{"fixed":"b3621031661ed10d6af511d7c41f512075357a00"},{"fixed":"c5970d3ee25b457ad2d78fe6e9662a12dae577cd"},{"fixed":"dd86461b71ff4a4f5194205896ae5f48f144240d"}],"database_specific":{"extracted_events":[{"introduced":"3.4.0"},{"fixed":"3.6.6"},{"introduced":"4.0.0-beta"},{"fixed":"4.0.0-rc1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["4.0.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45809.json","vanir_signatures_modified":"2026-08-07T21:32:31Z","vanir_signatures":[{"source":"https://github.com/opensips/opensips/commit/c5970d3ee25b457ad2d78fe6e9662a12dae577cd","target":{"file":"modules/presence/notify.c","function":"create_winfo_xml"},"deprecated":false,"digest":{"function_hash":"183821885697916348754699953055818722163","length":2528},"id":"CVE-2026-45809-3d216e5d","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/opensips/opensips/commit/dd86461b71ff4a4f5194205896ae5f48f144240d","target":{"file":"modules/presence/notify.c","function":"create_winfo_xml"},"deprecated":false,"digest":{"function_hash":"183821885697916348754699953055818722163","length":2528},"id":"CVE-2026-45809-6552f120","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["92711967930194413434373298487748522637","207029592527048478320583161783703490049","222977171143224573734795407850128024475","181718214887288236131761178719379504330","90908079061812501404018126926773218367","136675669830473365757410393279336641863","67694711868397253345108538836135562719","195868491343602345952019741565628650857","148194926361603152616941960260945734846","68780323381202982598413207753338807132","267775975522134175591330276817592825227","285555515541982983413164348894947969084","117036083369202793659756759572929934348","114290391985029173485579858732997151478","316253839681919968143278197172304977920","219578106303333885297147018675944648195"],"threshold":0.9},"id":"CVE-2026-45809-6be1e177","signature_type":"Line","signature_version":"v1","source":"https://github.com/opensips/opensips/commit/c5970d3ee25b457ad2d78fe6e9662a12dae577cd","target":{"file":"modules/presence/notify.c"}},{"deprecated":false,"digest":{"line_hashes":["92711967930194413434373298487748522637","207029592527048478320583161783703490049","222977171143224573734795407850128024475","181718214887288236131761178719379504330","90908079061812501404018126926773218367","136675669830473365757410393279336641863","67694711868397253345108538836135562719","195868491343602345952019741565628650857","148194926361603152616941960260945734846","68780323381202982598413207753338807132","267775975522134175591330276817592825227","285555515541982983413164348894947969084","117036083369202793659756759572929934348","114290391985029173485579858732997151478","316253839681919968143278197172304977920","219578106303333885297147018675944648195"],"threshold":0.9},"id":"CVE-2026-45809-f5a1be6b","signature_type":"Line","signature_version":"v1","source":"https://github.com/opensips/opensips/commit/dd86461b71ff4a4f5194205896ae5f48f144240d","target":{"file":"modules/presence/notify.c"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}