Technology · OpenSIPS
OpenSIPS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in OpenSIPS: 0 in the last 7 days and 8 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-46334, was published on 5 August 2026.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 3
- Exploited in the wild
- 0
About OpenSIPS
An open-source SIP proxy server used for voice, video, and instant messaging applications.
Latest OpenSIPS vulnerabilities
- CVE-2026-46334: OpenSIPS SDP bandwidth-line parsing denial of serviceinfoEPSS 0.7%
- CVE-2026-45809: OpenSIPS watcherinfo stack buffer overflowinfoCVSS 7.5EPSS 0.6%
- CVE-2026-45705: OpenSIPS out-of-bounds read in multipart body parsermediumCVSS 5.3EPSS 0.5%
- CVE-2026-45537: OpenSIPS construct_uri buffer overflowcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-45103: OpenSIPS integer overflow in TCP message framinghighCVSS 7.5EPSS 0.6%
- CVE-2026-45100: OpenSIPS buffer overflow in b64encode string transformationcriticalCVSS 9.1EPSS 0.8%
- CVE-2026-45084: OpenSIPS presence module denial of service in handle_publishinfoCVSS 7.5EPSS 0.7%
- CVE-2026-45538: OpenSIPS stack buffer overflow in sip_to_json header parsingcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-25554: OpenSIPS SQL injection in auth_jwt modulemediumCVSS 6.5EPSS 0.3%
Most severe OpenSIPS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-45538: OpenSIPS stack buffer overflow in sip_to_json header parsingcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-45100: OpenSIPS buffer overflow in b64encode string transformationcriticalCVSS 9.1EPSS 0.8%
- CVE-2026-45537: OpenSIPS construct_uri buffer overflowcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-45103: OpenSIPS integer overflow in TCP message framinghighCVSS 7.5EPSS 0.6%
- CVE-2026-25554: OpenSIPS SQL injection in auth_jwt modulemediumCVSS 6.5EPSS 0.3%
- CVE-2026-45705: OpenSIPS out-of-bounds read in multipart body parsermediumCVSS 5.3EPSS 0.5%
- CVE-2026-45084: OpenSIPS presence module denial of service in handle_publishinfoCVSS 7.5EPSS 0.7%
- CVE-2026-45809: OpenSIPS watcherinfo stack buffer overflowinfoCVSS 7.5EPSS 0.6%
- CVE-2026-46334: OpenSIPS SDP bandwidth-line parsing denial of serviceinfoEPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 8 | 3 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/opensips.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OpenSIPS vulnerabilities", https://junglewise.ai/threats/technologies/opensips, 28 September 2026.