OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the findlinedelimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near the end of the body, the function compares delimiter.len bytes (typically 20-70) starting from a position at or past the logical end of the body buffer, reading past the body boundary. The bug triggers when a SIP message has Content-Type: multipart/mixed with a boundary parameter and its body contains -- within two to three bytes of the body's end without being followed by the actual boundary delimiter. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45705.json",
"cwe_ids": [
"CWE-125"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1165.0,
"function_hash": "226109660663622823631909999628572278192"
},
"id": "CVE-2026-45705-0268cd07",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"function": "construct_uri",
"file": "msg_translator.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"85930018187884512745115767180453856631",
"9123448050024963639918296936378324161",
"92809748590602814031314121294972925619",
"240765678873066602221693786686058347090",
"182194714402083001125852811031434801325",
"210330180258749208161186560082503475195",
"274701893048541175074950407861772541431",
"18787012699178113669500224280464431920",
"205381219874839427522051611470170285208"
]
},
"id": "CVE-2026-45705-05eaa95d",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"file": "parser/parse_body.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"194553780228902367408282060407856839420",
"183826118522500325336916991386153275102",
"23609876740523779741945635475230307575",
"141747783010088878646037041870850259125"
]
},
"id": "CVE-2026-45705-107957fa",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"file": "net/proto_tcp/tcp_common.h"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"85930018187884512745115767180453856631",
"9123448050024963639918296936378324161",
"92809748590602814031314121294972925619",
"240765678873066602221693786686058347090",
"182194714402083001125852811031434801325",
"210330180258749208161186560082503475195",
"274701893048541175074950407861772541431",
"18787012699178113669500224280464431920",
"205381219874839427522051611470170285208"
]
},
"id": "CVE-2026-45705-122ca185",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"file": "parser/parse_body.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 571.0,
"function_hash": "239673843364076259551748090071822079551"
},
"id": "CVE-2026-45705-129c1a0a",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"function": "find_line_delimiter",
"file": "parser/parse_body.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 571.0,
"function_hash": "239673843364076259551748090071822079551"
},
"id": "CVE-2026-45705-22316bff",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"function": "find_line_delimiter",
"file": "parser/parse_body.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1165.0,
"function_hash": "226109660663622823631909999628572278192"
},
"id": "CVE-2026-45705-30c936c5",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"function": "construct_uri",
"file": "msg_translator.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"259792131642235888277525552403952949501",
"19727793969141095193342753458564901510",
"250027361493129396404438022515615142387",
"131530994763376973766044638250629325529"
]
},
"id": "CVE-2026-45705-45d036bf",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"file": "transformations.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5503.0,
"function_hash": "69285013667388920103612027740108265861"
},
"id": "CVE-2026-45705-471fb556",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"function": "tcp_parse_headers",
"file": "net/proto_tcp/tcp_common.h"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"194553780228902367408282060407856839420",
"183826118522500325336916991386153275102",
"23609876740523779741945635475230307575",
"141747783010088878646037041870850259125"
]
},
"id": "CVE-2026-45705-595b96e9",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"file": "net/proto_tcp/tcp_common.h"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"130220909244983205895730861006096440765",
"201398176700919108372473887128474278781",
"121445666154359984419269907102979981103",
"108167142466647012142512874289336928524"
]
},
"id": "CVE-2026-45705-8e374df9",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"file": "modules/sipmsgops/sipmsgops.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"19310062195480744222226083625835443064",
"339864232818495752804831665751736944949",
"240018973462300301157123594980096397708",
"269605422026381028125978291213120820099",
"250504334230145485243675626025849081370",
"118179321761923208172555936330597528500",
"315624634716116334899958124016993442152"
]
},
"id": "CVE-2026-45705-92f2e927",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"file": "msg_translator.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1822.0,
"function_hash": "192541007272035597802489654964185552143"
},
"id": "CVE-2026-45705-a77a39d4",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"function": "w_sip_to_json",
"file": "modules/sipmsgops/sipmsgops.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"130220909244983205895730861006096440765",
"201398176700919108372473887128474278781",
"121445666154359984419269907102979981103",
"108167142466647012142512874289336928524"
]
},
"id": "CVE-2026-45705-c40209c2",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"file": "modules/sipmsgops/sipmsgops.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5503.0,
"function_hash": "69285013667388920103612027740108265861"
},
"id": "CVE-2026-45705-cb92d957",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"function": "tcp_parse_headers",
"file": "net/proto_tcp/tcp_common.h"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 20896.0,
"function_hash": "140898031237516326815696325741558996037"
},
"id": "CVE-2026-45705-d98f0c26",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"function": "tr_eval_string",
"file": "transformations.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"19310062195480744222226083625835443064",
"339864232818495752804831665751736944949",
"240018973462300301157123594980096397708",
"269605422026381028125978291213120820099",
"250504334230145485243675626025849081370",
"118179321761923208172555936330597528500",
"315624634716116334899958124016993442152"
]
},
"id": "CVE-2026-45705-da732c9a",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"file": "msg_translator.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 20896.0,
"function_hash": "140898031237516326815696325741558996037"
},
"id": "CVE-2026-45705-dcf18d16",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"function": "tr_eval_string",
"file": "transformations.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"259792131642235888277525552403952949501",
"19727793969141095193342753458564901510",
"250027361493129396404438022515615142387",
"131530994763376973766044638250629325529"
]
},
"id": "CVE-2026-45705-e5c152fb",
"signature_type": "Line",
"source": "https://github.com/opensips/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb",
"target": {
"file": "transformations.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1822.0,
"function_hash": "192541007272035597802489654964185552143"
},
"id": "CVE-2026-45705-f2117fac",
"signature_type": "Function",
"source": "https://github.com/opensips/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668",
"target": {
"function": "w_sip_to_json",
"file": "modules/sipmsgops/sipmsgops.c"
}
}
]
"2026-08-07T21:32:31Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45705.json"