{"id":"CVE-2026-52022","details":"An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components","modified":"2026-09-03T08:07:10.889979Z","published":"2026-09-01T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52022.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52022.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52022"},{"type":"REPORT","url":"https://github.com/kamailio/kamailio/issues/4670"},{"type":"FIX","url":"https://github.com/kamailio/kamailio/commit/91c5ca751799db4f25a28a495350cc97f7c2f390"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kamailio/kamailio","events":[{"introduced":"0"},{"fixed":"91c5ca751799db4f25a28a495350cc97f7c2f390"}],"database_specific":{"source":"REFERENCES"}}],"versions":["sr_3.1_freeze","3.0_pre1","sr_before_modules_merge","before_dest_info_changes_2","before_tm_timers","new_timers","before_new_timers","tmp_pcl_tag_17368Js8","after_0_9_4_pkg_merge","last_merge_to_janakj","rel_0_9_0_root","after_makefile_merges","before_malloc_changes","before_db_api_changes","after_testing_0_8_12_r1_merge","before_testing_0_8_12_r1_merge","after_testing_0_8_12_r0_merge","before_testing_0_8_12_r0_merge","before_tcp_port_aliases","before_socket_info_lists","before_lumps_split","testing_0_8_12_root","v0_8_13dev-t16","v0_8_12dev_t13","v0_8_12dev_t05","v0_8_12dev-t03","v0_8_12_t02_merged_w_v0_8_11pre35","v0_8_11dev34","rel_0_8_11_root","v0_8_11pre29-prerelease-cd","v0_8_11pre29-prerelease","v0_8_11pre29","pre22","bflmpsvz","before_kill_repl_add_rm","v0_8_11_pre9","mem-fixes","v0_8_11pre8","old_mod_iface","after_xl","before_replication_patch","before_xl","pre6-tcp4","pre6-tcp5-tm","tcp2","wo_sp","post-zt","pre-zt","ser_0_8_10","ser_0_8_10_pre5","ser_0_8_10_pre4","ser_0_8_10_pre2","ser_0_8_10_pre3","myself_port_lo","new_hash","ser_0_8_9-release","ser_0_8_9","ser_0_8_8-final-cd-release","v0_8_8","fixstats","pre_fixstats","gpled","pregpl","listen_ifs","before_str2ip_changes","budvar","bigbang","pre-bigbang","srv","ipv6","ipv4_working","ser_0_8_7-0-unstable","ser_0_8_6-6-beer-release","ser_0_8_6-5-stable","ser_0-8-6-4","bogdan_final_version","ser_0839_errors","ser_0_8_3_2","ser_0_8_3_1","sip_083","ser_082","ser_081-plugins","sip_pre-plugin","ser_0_7","new_cfg_compiles","sr_simpleconfig","v03","v0_2"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/kamailio/kamailio/commit/91c5ca751799db4f25a28a495350cc97f7c2f390","target":{"function":"bind_usrloc","file":"src/modules/ims_usrloc_pcscf/usrloc.c"},"deprecated":false,"digest":{"function_hash":"125518537483774565992938065193219014130","length":961},"id":"CVE-2026-52022-2f402eaf","signature_type":"Function","signature_version":"v1"},{"target":{"file":"src/modules/ims_usrloc_pcscf/pcontact.c","function":"free_security"},"deprecated":false,"digest":{"function_hash":"216675546907776856518266329497123269671","length":697},"id":"CVE-2026-52022-6f60c8ef","signature_type":"Function","signature_version":"v1","source":"https://github.com/kamailio/kamailio/commit/91c5ca751799db4f25a28a495350cc97f7c2f390"},{"signature_version":"v1","source":"https://github.com/kamailio/kamailio/commit/91c5ca751799db4f25a28a495350cc97f7c2f390","target":{"file":"src/modules/ims_usrloc_pcscf/usrloc.c"},"deprecated":false,"digest":{"line_hashes":["87966889822828453077019162359258502099","144845778018568705734936397068010541019","37707670054391189582248894453730484740","305086005739633749219265787557731796268"],"threshold":0.9},"id":"CVE-2026-52022-97cd1764","signature_type":"Line"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/kamailio/kamailio/commit/91c5ca751799db4f25a28a495350cc97f7c2f390","target":{"file":"src/modules/ims_usrloc_pcscf/usrloc.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["74008760402000258209107808633887485100","313272144214067375275876774212077173672","207216520678018625425430307036242845594","157503833130542147550103246495820373738","220164467482345107550156306235979548238","270853031531404410161225549019550037094","221420835195486618572936289790169204691"]},"id":"CVE-2026-52022-c06e6856"},{"digest":{"line_hashes":["58145258059990616583934443736316514894","291913640052494821625719281299958973867","18179337824236489755613445391978769060","78289462677175590726252035625239328642","291269615414246282649256626604504771139","170760002304851566211891388688310050250","48078006340597503320635266867163064864","22007803796790978051271130926876556580","258441416083362208756473811022978221426","300347241837194113191141166713068499089","60176269707692166760309140059283812460","61248428501513939861724592072034009368","105647074229181165154643824856843014990","126184676408050728748163117370741456089","21855281101974610118909790110199738057","3346536848732547151066659734276502685","29739516415627364386480459750404288238","233395740415599494030231449841036187425","183878233815189370557316941666624062786"],"threshold":0.9},"id":"CVE-2026-52022-f629ca19","signature_type":"Line","signature_version":"v1","source":"https://github.com/kamailio/kamailio/commit/91c5ca751799db4f25a28a495350cc97f7c2f390","target":{"file":"src/modules/ims_usrloc_pcscf/pcontact.c"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52022.json","vanir_signatures_modified":"2026-09-03T08:07:10Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}