SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-120"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90780.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90780.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "9976261197102184989196215132784419593",
"length": 1216
},
"id": "CVE-2026-90780-08ed8213",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776",
"target": {
"file": "src/prepare_pcap.c",
"function": "prepare_dtmf"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"253922072885821488052009852498455109366",
"34586638566681625384682327254929602773",
"261283247031706384743989698715409911607",
"298123525681146494129287498515136892063"
],
"threshold": 0.9
},
"id": "CVE-2026-90780-123fd1ee",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776",
"target": {
"file": "src/prepare_pcap.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"252323527340657761663533910122171623862",
"260503324751946141377959341044348678704",
"266384485505044202640964179308171686210",
"50520102943716079966685877244799051816"
],
"threshold": 0.9
},
"id": "CVE-2026-90780-1ac6a568",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/sipp/sipp/commit/369b3c187f0ff96f3ec9795650820e80cf17c776",
"target": {
"file": "include/prepare_pcap.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "4010013218332515826330137127107684384",
"length": 2305
},
"id": "CVE-2026-90780-3e57f8ae",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/sipp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232",
"target": {
"file": "src/sip_parser.cpp",
"function": "get_header"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"270878178337179796163948195061363189304",
"281557019625715719839860253045860639712",
"226752716497095126807209708839036117537",
"289179327522368185994549133342300362022",
"267845824197525979675578341282382195977",
"211877094875746014077865965986823042064",
"268380276473079083049112374435952474290",
"83817919044602583794741446427164293357",
"158181676715012248769644952685864114494",
"303561741018978704516484132357808141160",
"85656332561523556575688748116516666084",
"242536510988150437675650901538348040382",
"23659888330178524426752913790080428265",
"99403128573327624505485695729880015341",
"204920408540664022113501192544203219490",
"130788194715158593530735191429498309998",
"276633382524005042205403592407195345184",
"117874116550151933333494394859819228390",
"235583863315640306488209519793813869026",
"206741012477988193784980980316016238962",
"132828472860452088338662313679281514043",
"145338850953087960149244561617583993440",
"108359392392091505736335543881274669997",
"100736367889195733514232923128896912019",
"225920783507633293108549339421510785336",
"233188428099199501602720648411386385053",
"152728959876342630290443858308919549650"
],
"threshold": 0.9
},
"id": "CVE-2026-90780-65d06ebf",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/sipp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232",
"target": {
"file": "src/sip_parser.cpp"
}
}
]
"2026-09-15T08:11:01Z"