{"id":"GHSA-8h6x-h86x-75wh","summary":"SIPGO: DoS via unvalidated WebSocket frame length","details":"### Summary\n\nThe WebSocket transport allocates a buffer from the frame payload length before validating its size, which can lead to an unauthenticated DoS.\n\n### Details\n\n`WSConnection.Read` allocates a buffer from the declared WebSocket frame length before reading the payload (https://github.com/emiago/sipgo/blob/v1.4.0/sip/transport_ws.go#L400):\n\n```go\ndata := make([]byte, header.Length)   // header.Length is client-controlled, up to 2^63-1 (int64)\n```\n\n- `NextFrame()` reads only the frame header and never checks the length: `wsutil.NewReader` is created with no [`MaxFrameSize`](https://pkg.go.dev/github.com/gobwas/ws@v1.3.2/wsutil#Reader.MaxFrameSize) (`0` = unlimited). `ParseMaxMessageLength` applies only downstream, not here.\n- A value above the max slice size (e.g. `2^63-1`) panics `make`. sipgo does not recover from this panic, so it crashes the whole server process.\n\n### PoC\n\nTested on emiago/sipgo v1.4.0 (latest).\n\nAfter a normal WebSocket handshake, send one masked text frame consisting of the header only (no payload), declaring a huge length. The allocation runs as soon as the header is read.\n\n```\n0x81                                            FIN + text opcode\n0xFF                                            MASK bit + length marker 127 (8-byte length follows)\n0x7F FF FF FF FF FF FF FF                        declared length = 2^63-1  -\u003e  make panics (crash)\n\u003c4-byte masking key\u003e\n(no payload)\n```\n\nThis crashes the server process:\n\n```\npanic: runtime error: makeslice: len out of range\n\ngoroutine 23 [running]:\ngithub.com/emiago/sipgo/sip.(*WSConnection).Read(...)\n        /path/to/pkg/mod/github.com/emiago/sipgo@v1.4.0/sip/transport_ws.go:400 +0x2df\ngithub.com/emiago/sipgo/sip.(*TransportWS).readConnection(...)\n        /path/to/pkg/mod/github.com/emiago/sipgo@v1.4.0/sip/transport_ws.go:194 +0x266\ncreated by github.com/emiago/sipgo/sip.(*TransportWS).initConnection in goroutine 21\n        /path/to/pkg/mod/github.com/emiago/sipgo@v1.4.0/sip/transport_ws.go:167 +0x268\n```\n\n### Suggested Fix\n\nSet [`MaxFrameSize`](https://pkg.go.dev/github.com/gobwas/ws@v1.3.2/wsutil#Reader.MaxFrameSize) on the `wsutil.NewReader`.\n\n### Impact\n\nUnauthenticated DoS. Any service using `sipgo` with a WS/WSS transport can be crashed by a single frame (panic), or forced to run out of memory.","aliases":["CVE-2026-77322","GO-2026-6559"],"modified":"2026-10-01T20:56:11.724309977Z","published":"2026-09-22T20:34:30Z","database_specific":{"github_reviewed_at":"2026-09-22T20:34:30Z","nvd_published_at":null,"cwe_ids":["CWE-789"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/emiago/sipgo/security/advisories/GHSA-8h6x-h86x-75wh"},{"type":"WEB","url":"https://github.com/emiago/sipgo/commit/769e4bc958376e2363566c8f7042202b410becdc"},{"type":"PACKAGE","url":"https://github.com/emiago/sipgo"},{"type":"WEB","url":"https://github.com/emiago/sipgo/releases/tag/v1.4.3"}],"affected":[{"package":{"name":"github.com/emiago/sipgo","ecosystem":"Go","purl":"pkg:golang/github.com/emiago/sipgo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-8h6x-h86x-75wh/GHSA-8h6x-h86x-75wh.json","last_known_affected_version_range":"\u003c= 1.4.2"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}