Junglewise Threat Intelligence

CVE-2026-90778: SIPp buffer overflow in get_peer_tag() function

CVE-2026-90778 · Severity: high · CVSS 7.5 · Published 2026-09-13

Technologies: SIPp. Vendors: SIPp.

Executive brief

SIPp is a widely-used testing tool for Session Initiation Protocol (SIP) applications. The tool contains a buffer overflow vulnerability in its SIP message parser that can be triggered by sending a specially crafted message with an oversized tag parameter. An unauthenticated attacker on the network can exploit this to crash the SIPp process, causing testing services to become unavailable.

Technical details

The vulnerability is a classic stack-based buffer overflow in the get_peer_tag() function within the SIP parser (sip_parser.cpp). The function fails to properly validate the length of the tag parameter in SIP To headers, allowing an attacker to write beyond the bounds of a static buffer when processing tag parameters of 2049 bytes or more. The attack requires no authentication and is triggered by sending a single crafted SIP message over the network. Successful exploitation results in process crash (denial of service); remote code execution is theoretically possible depending on memory layout and compiler protections. Patches are expected to be available in versions after 3.7.7.

Affected products

  • SIPp SIPp through 3.7.7

Timeline

  • 2026-09-13: disclosed

References

Related threats