Vendor
OpenSIPS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in OpenSIPS: 0 in the last 7 days and 8 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-46334, was published on 5 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 3
- Exploited in the wild
- 0
About OpenSIPS
OpenSIPS is an open-source project focused on the development of a multi-functional SIP server.
OpenSIPS technologies
Latest OpenSIPS vulnerabilities
- CVE-2026-46334: OpenSIPS SDP bandwidth-line parsing denial of serviceinfoEPSS 0.7%
- CVE-2026-45809: OpenSIPS watcherinfo stack buffer overflowinfoCVSS 7.5EPSS 0.6%
- CVE-2026-45705: OpenSIPS out-of-bounds read in multipart body parsermediumCVSS 5.3EPSS 0.5%
- CVE-2026-45537: OpenSIPS construct_uri buffer overflowcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-45103: OpenSIPS integer overflow in TCP message framinghighCVSS 7.5EPSS 0.6%
- CVE-2026-45100: OpenSIPS buffer overflow in b64encode string transformationcriticalCVSS 9.1EPSS 0.8%
- CVE-2026-45084: OpenSIPS presence module denial of service in handle_publishinfoCVSS 7.5EPSS 0.7%
- CVE-2026-45538: OpenSIPS stack buffer overflow in sip_to_json header parsingcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-36670: OpenSIPS Control Panel SQL injection in alias_management moduleinfoCVSS 8.8
- CVE-2026-25554: OpenSIPS SQL injection in auth_jwt modulemediumCVSS 6.5EPSS 0.3%
Most severe OpenSIPS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-45538: OpenSIPS stack buffer overflow in sip_to_json header parsingcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-45100: OpenSIPS buffer overflow in b64encode string transformationcriticalCVSS 9.1EPSS 0.8%
- CVE-2026-45537: OpenSIPS construct_uri buffer overflowcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-45103: OpenSIPS integer overflow in TCP message framinghighCVSS 7.5EPSS 0.6%
- CVE-2026-25554: OpenSIPS SQL injection in auth_jwt modulemediumCVSS 6.5EPSS 0.3%
- CVE-2026-45705: OpenSIPS out-of-bounds read in multipart body parsermediumCVSS 5.3EPSS 0.5%
- CVE-2026-36670: OpenSIPS Control Panel SQL injection in alias_management moduleinfoCVSS 8.8
- CVE-2026-45084: OpenSIPS presence module denial of service in handle_publishinfoCVSS 7.5EPSS 0.7%
- CVE-2026-45809: OpenSIPS watcherinfo stack buffer overflowinfoCVSS 7.5EPSS 0.6%
- CVE-2026-46334: OpenSIPS SDP bandwidth-line parsing denial of serviceinfoEPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 8 | 3 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/opensips.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OpenSIPS vulnerabilities", https://junglewise.ai/threats/vendors/opensips, 26 September 2026.