{"id":"CVE-2026-90558","summary":"sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers","details":"sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.","modified":"2026-09-14T08:02:09.838593Z","published":"2026-09-12T18:06:42.389Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90558.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90558.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90558"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sngrep-through-1.8.4-stack-buffer-overflow-via-sip-headers"},{"type":"FIX","url":"https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b"},{"type":"PACKAGE","url":"https://github.com/irontec/sngrep"},{"type":"ARTICLE","url":"https://github.com/irontec/sngrep/blob/v1.8.4/src/sip_call.c#L260"},{"type":"ARTICLE","url":"https://github.com/irontec/sngrep/blob/v1.8.4/src/sip_msg.c#L150"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/irontec/sngrep","events":[{"introduced":"0"},{"fixed":"9c370866afaf5ccb258bf03848b2d22f30cf61bd"},{"fixed":"1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.8.4"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v1.8.4","v1.8.3","v1.8.2","v1.8.1","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.10","v1.4.9","v1.4.8","v1.4.7","v1.4.6","v1.4.5","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.1","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v0.4.2","v0.4.1","v0.4.0","v0.3.2","v0.3.1","v0.3.0","v0.2.2","v0.2.1","v0.2.0","v0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90558.json","vanir_signatures_modified":"2026-09-14T08:02:09Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["279440582250578296193840475496453636117","96870954802844148955344172519438319270","8094867290165249734434810269959068088","297511303357079697933266456306528370360","196393278493849693366939757191608349711","17179381863115998611349784033943188810","129353944419138143220011652984552702321","85299020315766441058497073403285284845","75933050253449810368859755382870999","233905155149612973558473347240536481364","64555589292554117084186246274178940581","140741993166649076060291042121912787752","104813676274187598714395216943421543789","204973515369955084457104884713665744576"],"threshold":0.9},"id":"CVE-2026-90558-17cf333f","signature_type":"Line","signature_version":"v1","source":"https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b","target":{"file":"src/sip_msg.c"}},{"target":{"function":"call_get_attribute","file":"src/sip_call.c"},"deprecated":false,"digest":{"function_hash":"111125288767540778761537095320244449985","length":1317},"id":"CVE-2026-90558-23b366aa","signature_type":"Function","signature_version":"v1","source":"https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b"},{"signature_version":"v1","source":"https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b","target":{"file":"src/sip_msg.c","function":"msg_get_attribute"},"deprecated":false,"digest":{"function_hash":"63391084472868686839550974522782033342","length":1739},"id":"CVE-2026-90558-6067a2a9","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["229021116162234078848432265344554651196","319559975979939562799426630552879723046","202064902025601054892336416377651349376","296003520884524200649739642727261651603","161197051861708840588088969754199427224","191170365226701352143231910222679125056","185136573123026610750816797542454565353","315710217737691059426714554131382485170","215779271173923118255330335610489458848","61170910061658189365619611834386102885","207396553284351806217410715140466289921"],"threshold":0.9},"id":"CVE-2026-90558-6ac04c2c","signature_type":"Line","signature_version":"v1","source":"https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b","target":{"file":"src/sip_call.c"}},{"source":"https://github.com/irontec/sngrep/commit/9c370866afaf5ccb258bf03848b2d22f30cf61bd","target":{"file":"tests/test_012.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["310538024815724064236695882077102450632","21822706051125927168253165853127936377","150324856343534386096464913747835409221","171981819089489227909174448122472781239","307523643379423248034281136856131709679","154640463299133256708165839214375737209","92954546007576926056564197872040921182"]},"id":"CVE-2026-90558-fbca0543","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}