CVE-2026-90779

Source
https://cve.org/CVERecord?id=CVE-2026-90779
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90779.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90779
Published
2026-09-13T11:42:28Z
Modified
2026-09-16T08:09:45Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter
Details

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-121"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90779.json"
}
References

Affected packages

Git / github.com/sipp/sipp

Affected ranges

Type
GIT
Repo
https://github.com/sipp/sipp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.7.7"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.4-beta1
3.4-beta2
v3.*
v3.4.1
v3.5.0
v3.5.0-rc1
v3.5.0-rc2
v3.5.0-rc4
v3.5.1-rc1
v3.6-dev
v3.6.0
v3.6.0_rc1
v3.7-dev
v3.7.0
v3.7.0_rc1
v3.7.1
v3.7.2
v3.7.3
v3.7.5
v3.7.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90779.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "9976261197102184989196215132784419593",
            "length": 1216
        },
        "id": "CVE-2026-90779-08ed8213",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776",
        "target": {
            "file": "src/prepare_pcap.c",
            "function": "prepare_dtmf"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "253922072885821488052009852498455109366",
                "34586638566681625384682327254929602773",
                "261283247031706384743989698715409911607",
                "298123525681146494129287498515136892063"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-90779-123fd1ee",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776",
        "target": {
            "file": "src/prepare_pcap.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "252323527340657761663533910122171623862",
                "260503324751946141377959341044348678704",
                "266384485505044202640964179308171686210",
                "50520102943716079966685877244799051816"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-90779-1ac6a568",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776",
        "target": {
            "file": "include/prepare_pcap.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "272655781295700440033255931196775378875",
            "length": 1584
        },
        "id": "CVE-2026-90779-8e422d75",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/sipp/sipp/commit/1d4a5622bea34d0b5cdff333e6b5734608e30af7",
        "target": {
            "file": "src/auth.cpp",
            "function": "createAuthHeader"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "124341802793827089946765421589429529441",
                "173967929672885655827398598679834291408",
                "177159558675663488573672167036968157372",
                "98707615778113804829966795241830409397",
                "49269686409717794407693772224571075046",
                "286482285018539266061095127685398109376",
                "314260532159957039417265428906017241000",
                "115662733980193889599238957486292395076",
                "78259846757919196522980420459721020154",
                "187001006497358060075961279763535420451",
                "145872507985190503826988008353323061297",
                "268644509643034483966382941673200849268",
                "298160898338246989194685829568788963747",
                "128382950524341504630049657530567576996",
                "197850149046904233672957869950140791052",
                "16208948970243082542168294146801497050"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-90779-ad0783e3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sipp/sipp/commit/1d4a5622bea34d0b5cdff333e6b5734608e30af7",
        "target": {
            "file": "src/auth.cpp"
        }
    }
]
vanir_signatures_modified
"2026-09-16T08:09:45Z"