CVE-2026-45705

Source
https://cve.org/CVERecord?id=CVE-2026-45705
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45705.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45705
Aliases
  • GHSA-chxf-9368-fqcp
Downstream
Published
2026-08-04T23:16:31.543Z
Modified
2026-08-07T21:32:31.171528Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
OpenSIPS: OOB Read in Multipart Body Boundary Parsing
Details

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the findlinedelimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near the end of the body, the function compares delimiter.len bytes (typically 20-70) starting from a position at or past the logical end of the body buffer, reading past the body boundary. The bug triggers when a SIP message has Content-Type: multipart/mixed with a boundary parameter and its body contains -- within two to three bytes of the body's end without being followed by the actual boundary delimiter. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45705.json",
    "cwe_ids": [
        "CWE-125"
    ]
}
References

Affected packages

Git / github.com/opensips/opensips

Affected ranges

Type
GIT
Repo
https://github.com/opensips/opensips
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.4.0"
        },
        {
            "fixed": "3.6.6"
        },
        {
            "introduced": "4.0.0-beta"
        },
        {
            "fixed": "4.0.0-rc1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.0.0-beta

Database specific

vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1165.0,
            "function_hash": "226109660663622823631909999628572278192"
        },
        "id": "CVE-2026-45705-0268cd07",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "function": "construct_uri",
            "file": "msg_translator.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "85930018187884512745115767180453856631",
                "9123448050024963639918296936378324161",
                "92809748590602814031314121294972925619",
                "240765678873066602221693786686058347090",
                "182194714402083001125852811031434801325",
                "210330180258749208161186560082503475195",
                "274701893048541175074950407861772541431",
                "18787012699178113669500224280464431920",
                "205381219874839427522051611470170285208"
            ]
        },
        "id": "CVE-2026-45705-05eaa95d",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "file": "parser/parse_body.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "194553780228902367408282060407856839420",
                "183826118522500325336916991386153275102",
                "23609876740523779741945635475230307575",
                "141747783010088878646037041870850259125"
            ]
        },
        "id": "CVE-2026-45705-107957fa",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "file": "net/proto_tcp/tcp_common.h"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "85930018187884512745115767180453856631",
                "9123448050024963639918296936378324161",
                "92809748590602814031314121294972925619",
                "240765678873066602221693786686058347090",
                "182194714402083001125852811031434801325",
                "210330180258749208161186560082503475195",
                "274701893048541175074950407861772541431",
                "18787012699178113669500224280464431920",
                "205381219874839427522051611470170285208"
            ]
        },
        "id": "CVE-2026-45705-122ca185",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "file": "parser/parse_body.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 571.0,
            "function_hash": "239673843364076259551748090071822079551"
        },
        "id": "CVE-2026-45705-129c1a0a",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "function": "find_line_delimiter",
            "file": "parser/parse_body.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 571.0,
            "function_hash": "239673843364076259551748090071822079551"
        },
        "id": "CVE-2026-45705-22316bff",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "function": "find_line_delimiter",
            "file": "parser/parse_body.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1165.0,
            "function_hash": "226109660663622823631909999628572278192"
        },
        "id": "CVE-2026-45705-30c936c5",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "function": "construct_uri",
            "file": "msg_translator.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "259792131642235888277525552403952949501",
                "19727793969141095193342753458564901510",
                "250027361493129396404438022515615142387",
                "131530994763376973766044638250629325529"
            ]
        },
        "id": "CVE-2026-45705-45d036bf",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "file": "transformations.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 5503.0,
            "function_hash": "69285013667388920103612027740108265861"
        },
        "id": "CVE-2026-45705-471fb556",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "function": "tcp_parse_headers",
            "file": "net/proto_tcp/tcp_common.h"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "194553780228902367408282060407856839420",
                "183826118522500325336916991386153275102",
                "23609876740523779741945635475230307575",
                "141747783010088878646037041870850259125"
            ]
        },
        "id": "CVE-2026-45705-595b96e9",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "file": "net/proto_tcp/tcp_common.h"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "130220909244983205895730861006096440765",
                "201398176700919108372473887128474278781",
                "121445666154359984419269907102979981103",
                "108167142466647012142512874289336928524"
            ]
        },
        "id": "CVE-2026-45705-8e374df9",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "file": "modules/sipmsgops/sipmsgops.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "19310062195480744222226083625835443064",
                "339864232818495752804831665751736944949",
                "240018973462300301157123594980096397708",
                "269605422026381028125978291213120820099",
                "250504334230145485243675626025849081370",
                "118179321761923208172555936330597528500",
                "315624634716116334899958124016993442152"
            ]
        },
        "id": "CVE-2026-45705-92f2e927",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "file": "msg_translator.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1822.0,
            "function_hash": "192541007272035597802489654964185552143"
        },
        "id": "CVE-2026-45705-a77a39d4",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "function": "w_sip_to_json",
            "file": "modules/sipmsgops/sipmsgops.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "130220909244983205895730861006096440765",
                "201398176700919108372473887128474278781",
                "121445666154359984419269907102979981103",
                "108167142466647012142512874289336928524"
            ]
        },
        "id": "CVE-2026-45705-c40209c2",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "file": "modules/sipmsgops/sipmsgops.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 5503.0,
            "function_hash": "69285013667388920103612027740108265861"
        },
        "id": "CVE-2026-45705-cb92d957",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "function": "tcp_parse_headers",
            "file": "net/proto_tcp/tcp_common.h"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 20896.0,
            "function_hash": "140898031237516326815696325741558996037"
        },
        "id": "CVE-2026-45705-d98f0c26",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "function": "tr_eval_string",
            "file": "transformations.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "19310062195480744222226083625835443064",
                "339864232818495752804831665751736944949",
                "240018973462300301157123594980096397708",
                "269605422026381028125978291213120820099",
                "250504334230145485243675626025849081370",
                "118179321761923208172555936330597528500",
                "315624634716116334899958124016993442152"
            ]
        },
        "id": "CVE-2026-45705-da732c9a",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "file": "msg_translator.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 20896.0,
            "function_hash": "140898031237516326815696325741558996037"
        },
        "id": "CVE-2026-45705-dcf18d16",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "function": "tr_eval_string",
            "file": "transformations.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "259792131642235888277525552403952949501",
                "19727793969141095193342753458564901510",
                "250027361493129396404438022515615142387",
                "131530994763376973766044638250629325529"
            ]
        },
        "id": "CVE-2026-45705-e5c152fb",
        "signature_type": "Line",
        "source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
        "target": {
            "file": "transformations.c"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1822.0,
            "function_hash": "192541007272035597802489654964185552143"
        },
        "id": "CVE-2026-45705-f2117fac",
        "signature_type": "Function",
        "source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
        "target": {
            "function": "w_sip_to_json",
            "file": "modules/sipmsgops/sipmsgops.c"
        }
    }
]
vanir_signatures_modified
"2026-08-07T21:32:31Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45705.json"