{"id":"CVE-2026-46334","summary":"OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning","details":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","aliases":["GHSA-rh36-mhpv-cx2r"],"modified":"2026-09-10T08:13:46.966346Z","published":"2026-08-04T23:50:57.147Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46334.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-476"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46334.json"},{"type":"ADVISORY","url":"https://github.com/OpenSIPS/opensips/security/advisories/GHSA-rh36-mhpv-cx2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46334"},{"type":"FIX","url":"https://github.com/OpenSIPS/opensips/commit/8fe74b01f6fbf86c0b5e290735275530cb65e0fb"},{"type":"FIX","url":"https://github.com/OpenSIPS/opensips/commit/ac5309d5b8206cd3dbe1b4e01567c8db1ce31444"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensips/opensips","events":[{"introduced":"f3e0d5333913bcaace4c8f8711871550accca63f"},{"introduced":"985272ff3d7ebc5e9f24ad9f8fcf8b1d2549f1b6"},{"fixed":"26c0c4e3364806e77c2915b1c3e03bf9bd90dccd"},{"fixed":"b3621031661ed10d6af511d7c41f512075357a00"},{"fixed":"8fe74b01f6fbf86c0b5e290735275530cb65e0fb"},{"fixed":"ac5309d5b8206cd3dbe1b4e01567c8db1ce31444"}],"database_specific":{"extracted_events":[{"introduced":"3.4.0"},{"fixed":"3.6.6"},{"introduced":"4.0.0-beta"},{"fixed":"4.0.0-rc1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["4.0.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46334.json","vanir_signatures_modified":"2026-09-10T08:13:46Z","vanir_signatures":[{"target":{"file":"parser/sdp/sdp_helpr_funcs.c","function":"extract_bwidth"},"deprecated":false,"digest":{"function_hash":"5604857722602776583799514757242078512","length":845},"id":"CVE-2026-46334-3377b23d","signature_type":"Function","signature_version":"v1","source":"https://github.com/opensips/opensips/commit/ac5309d5b8206cd3dbe1b4e01567c8db1ce31444"},{"source":"https://github.com/opensips/opensips/commit/8fe74b01f6fbf86c0b5e290735275530cb65e0fb","target":{"function":"extract_bwidth","file":"parser/sdp/sdp_helpr_funcs.c"},"deprecated":false,"digest":{"function_hash":"5604857722602776583799514757242078512","length":845},"id":"CVE-2026-46334-37d56786","signature_type":"Function","signature_version":"v1"},{"target":{"file":"parser/sdp/sdp_helpr_funcs.c"},"deprecated":false,"digest":{"line_hashes":["274649987760794002626772319524306672109","154530106979246228642759224874773361461","339343931547276723309221969198126372729","250102622850963174058274054789647244679","130136018083534187113484736086847209594","321572748819175552065341886633798447776","62322137361923679437925903676935188220","260095954621106649747531507293077588814","196886608502580785253007079552070829300","143953596499609235330363533897334721431","328298681082458461317548890541520591916","259627427995524275893870681290186036715","173743397329995997852266847536505079447","339156684378807955336809022660260933937","168244600950864165149690995591376149559","222342274989249205486172805417406596012","85355716432492371283438988232430160303","149435499097502926279200116635861500870","128235114157661571028685514861636620500","93757441748574527643332219990470221670","259980706223435925707360665094414219380","332489586934144957364758464825987682381","106822551505323063470592065723657689718","228886260889457454028525670053294034838","102366029156877985027169591388104625871","163441661206212564780360257060654282932"],"threshold":0.9},"id":"CVE-2026-46334-38833c9e","signature_type":"Line","signature_version":"v1","source":"https://github.com/opensips/opensips/commit/ac5309d5b8206cd3dbe1b4e01567c8db1ce31444"},{"source":"https://github.com/opensips/opensips/commit/8fe74b01f6fbf86c0b5e290735275530cb65e0fb","target":{"file":"parser/sdp/sdp_helpr_funcs.c"},"deprecated":false,"digest":{"line_hashes":["274649987760794002626772319524306672109","154530106979246228642759224874773361461","339343931547276723309221969198126372729","250102622850963174058274054789647244679","130136018083534187113484736086847209594","321572748819175552065341886633798447776","62322137361923679437925903676935188220","260095954621106649747531507293077588814","196886608502580785253007079552070829300","143953596499609235330363533897334721431","328298681082458461317548890541520591916","259627427995524275893870681290186036715","173743397329995997852266847536505079447","339156684378807955336809022660260933937","168244600950864165149690995591376149559","222342274989249205486172805417406596012","85355716432492371283438988232430160303","149435499097502926279200116635861500870","128235114157661571028685514861636620500","93757441748574527643332219990470221670","259980706223435925707360665094414219380","332489586934144957364758464825987682381","106822551505323063470592065723657689718","228886260889457454028525670053294034838","102366029156877985027169591388104625871","163441661206212564780360257060654282932"],"threshold":0.9},"id":"CVE-2026-46334-547fb548","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}