sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90558.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90558.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"279440582250578296193840475496453636117",
"96870954802844148955344172519438319270",
"8094867290165249734434810269959068088",
"297511303357079697933266456306528370360",
"196393278493849693366939757191608349711",
"17179381863115998611349784033943188810",
"129353944419138143220011652984552702321",
"85299020315766441058497073403285284845",
"75933050253449810368859755382870999",
"233905155149612973558473347240536481364",
"64555589292554117084186246274178940581",
"140741993166649076060291042121912787752",
"104813676274187598714395216943421543789",
"204973515369955084457104884713665744576"
],
"threshold": 0.9
},
"id": "CVE-2026-90558-17cf333f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b",
"target": {
"file": "src/sip_msg.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "111125288767540778761537095320244449985",
"length": 1317
},
"id": "CVE-2026-90558-23b366aa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b",
"target": {
"file": "src/sip_call.c",
"function": "call_get_attribute"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "63391084472868686839550974522782033342",
"length": 1739
},
"id": "CVE-2026-90558-6067a2a9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b",
"target": {
"file": "src/sip_msg.c",
"function": "msg_get_attribute"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"229021116162234078848432265344554651196",
"319559975979939562799426630552879723046",
"202064902025601054892336416377651349376",
"296003520884524200649739642727261651603",
"161197051861708840588088969754199427224",
"191170365226701352143231910222679125056",
"185136573123026610750816797542454565353",
"315710217737691059426714554131382485170",
"215779271173923118255330335610489458848",
"61170910061658189365619611834386102885",
"207396553284351806217410715140466289921"
],
"threshold": 0.9
},
"id": "CVE-2026-90558-6ac04c2c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b",
"target": {
"file": "src/sip_call.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"310538024815724064236695882077102450632",
"21822706051125927168253165853127936377",
"150324856343534386096464913747835409221",
"171981819089489227909174448122472781239",
"307523643379423248034281136856131709679",
"154640463299133256708165839214375737209",
"92954546007576926056564197872040921182"
],
"threshold": 0.9
},
"id": "CVE-2026-90558-fbca0543",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/irontec/sngrep/commit/9c370866afaf5ccb258bf03848b2d22f30cf61bd",
"target": {
"file": "tests/test_012.c"
}
}
]
"2026-09-14T08:02:09Z"