{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-45103","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-05-08T19:27:26.699Z","datePublished":"2026-08-04T21:56:57.422Z","dateUpdated":"2026-08-05T17:55:45.043Z"},"containers":{"cna":{"title":"OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow","problemTypes":[{"descriptions":[{"cweId":"CWE-190","lang":"en","description":"CWE-190: Integer Overflow or Wraparound","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jv35-555v-54jh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jv35-555v-54jh"},{"name":"https://github.com/OpenSIPS/opensips/commit/4d23613b","tags":["x_refsource_MISC"],"url":"https://github.com/OpenSIPS/opensips/commit/4d23613b"},{"name":"https://github.com/OpenSIPS/opensips/commit/5f103eff","tags":["x_refsource_MISC"],"url":"https://github.com/OpenSIPS/opensips/commit/5f103eff"}],"affected":[{"vendor":"OpenSIPS","product":"opensips","versions":[{"version":">= 3.4.0, < 3.6.6","status":"affected"},{"version":">= 4.0.0-beta, < 4.0.0-rc1","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-08-04T21:56:57.422Z"},"descriptions":[{"lang":"en","value":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be processed as a separate message and enabling SIP message smuggling. Because Content-Length is parsed in the transport layer before authentication, an unauthenticated, network-based attacker can smuggle arbitrary SIP messages over any TCP-based transport (proto_tcp, proto_tls, proto_ws, proto_wss) on any instance with TCP enabled, with no routing-script preconditions. This allows smuggled messages to bypass front-end SBC/proxy security policies, inherit the connection's authentication context, and evade rate limiting. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1."}],"source":{"advisory":"GHSA-jv35-555v-54jh","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-05T17:53:22.085357Z","id":"CVE-2026-45103","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-05T17:55:45.043Z"}}]}}