{"id":"CVE-2026-90780","summary":"SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content","details":"SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.","modified":"2026-09-15T08:11:01.572474Z","published":"2026-09-13T11:42:29.104Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90780.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90780.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90780"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sipp-through-3.7.7-buffer-overflow-via-oversized-sip-header-content"},{"type":"FIX","url":"https://github.com/SIPp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232"},{"type":"FIX","url":"https://github.com/SIPp/sipp/pull/881"},{"type":"PACKAGE","url":"https://github.com/SIPp/sipp"},{"type":"ARTICLE","url":"https://github.com/SIPp/sipp/blob/v3.7.7/src/sip_parser.cpp#L164-L227"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sipp/sipp","events":[{"introduced":"0"},{"fixed":"369b3c187f0ff96f3ec9795650820e80cf17c776"},{"fixed":"8ddfb43359703e665041a955543e07f504f80232"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.7.7"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v3.7.7","v3.7.6","v3.7.5","v3.7.3","v3.7.2","v3.7.1","v3.7.0","v3.7.0_rc1","v3.7-dev","v3.6.0","v3.6.0_rc1","v3.6-dev","v3.5.1-rc1","v3.5.0","v3.5.0-rc4","v3.5.0-rc2","v3.5.0-rc1","v3.4.1","3.4-beta2","3.4-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90780.json","vanir_signatures_modified":"2026-09-15T08:11:01Z","vanir_signatures":[{"id":"CVE-2026-90780-08ed8213","signature_type":"Function","signature_version":"v1","source":"https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776","target":{"file":"src/prepare_pcap.c","function":"prepare_dtmf"},"deprecated":false,"digest":{"function_hash":"9976261197102184989196215132784419593","length":1216}},{"deprecated":false,"digest":{"line_hashes":["253922072885821488052009852498455109366","34586638566681625384682327254929602773","261283247031706384743989698715409911607","298123525681146494129287498515136892063"],"threshold":0.9},"id":"CVE-2026-90780-123fd1ee","signature_type":"Line","signature_version":"v1","source":"https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776","target":{"file":"src/prepare_pcap.c"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776","target":{"file":"include/prepare_pcap.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["252323527340657761663533910122171623862","260503324751946141377959341044348678704","266384485505044202640964179308171686210","50520102943716079966685877244799051816"]},"id":"CVE-2026-90780-1ac6a568"},{"source":"https://github.com/sipp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232","target":{"file":"src/sip_parser.cpp","function":"get_header"},"deprecated":false,"digest":{"function_hash":"4010013218332515826330137127107684384","length":2305},"id":"CVE-2026-90780-3e57f8ae","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["270878178337179796163948195061363189304","281557019625715719839860253045860639712","226752716497095126807209708839036117537","289179327522368185994549133342300362022","267845824197525979675578341282382195977","211877094875746014077865965986823042064","268380276473079083049112374435952474290","83817919044602583794741446427164293357","158181676715012248769644952685864114494","303561741018978704516484132357808141160","85656332561523556575688748116516666084","242536510988150437675650901538348040382","23659888330178524426752913790080428265","99403128573327624505485695729880015341","204920408540664022113501192544203219490","130788194715158593530735191429498309998","276633382524005042205403592407195345184","117874116550151933333494394859819228390","235583863315640306488209519793813869026","206741012477988193784980980316016238962","132828472860452088338662313679281514043","145338850953087960149244561617583993440","108359392392091505736335543881274669997","100736367889195733514232923128896912019","225920783507633293108549339421510785336","233188428099199501602720648411386385053","152728959876342630290443858308919549650"],"threshold":0.9},"id":"CVE-2026-90780-65d06ebf","signature_type":"Line","signature_version":"v1","source":"https://github.com/sipp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232","target":{"file":"src/sip_parser.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}