An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52023.json"
}{
"cpe": "cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "6.1.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52023.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "116828194652683753321392469441402438381",
"length": 2418
},
"id": "CVE-2026-52023-2763edb5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/kamailio/kamailio/commit/722c06b3efc53ccb369ce812c685c7d069508187",
"target": {
"file": "src/modules/ims_registrar_pcscf/sec_agree.c",
"function": "parse_sec_agree"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"12084986634156765647148718525276466660",
"32583586127040675767447764902947172589",
"99837190248917914247791332185218599524",
"68358940947506617454460800044141755231",
"284157240479457830649001255956373266583",
"4130054736324508012714598798075168888",
"145158083848719949532104817046020224795",
"323176148634908985472422518036879308055",
"183923856432614665773152632610454871038",
"176118923420743935934794763867172260337",
"229512807910842828314101454005520128274"
],
"threshold": 0.9
},
"id": "CVE-2026-52023-ca501d7a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/kamailio/kamailio/commit/722c06b3efc53ccb369ce812c685c7d069508187",
"target": {
"file": "src/modules/ims_registrar_pcscf/sec_agree.c"
}
}
]
"2026-09-17T08:15:52Z"