{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90778","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-13T11:15:50.569Z","datePublished":"2026-09-13T11:42:27.756Z","dateUpdated":"2026-09-24T14:21:58.116Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-24T14:21:58.116Z"},"datePublic":"2026-08-24T00:00:00.000Z","title":"SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag","descriptions":[{"lang":"en","value":"SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')","cweId":"CWE-120","type":"CWE"}]}],"affected":[{"vendor":"SIPp","product":"sipp","defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","versionType":"semver","lessThanOrEqual":"3.7.7"}],"repo":"https://github.com/SIPp/sipp"}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}],"references":[{"url":"https://github.com/SIPp/sipp/pull/879","name":"Pull Request #879","tags":["patch","issue-tracking"]},{"url":"https://github.com/SIPp/sipp/commit/ddf22d1a54e0396b2e18ebaf4cf5a3fa860e5da4","name":"Patch Commit","tags":["patch"]},{"url":"https://github.com/SIPp/sipp/blob/v3.7.7/src/sip_parser.cpp#L76-L113","name":"Unbounded copy in get_peer_tag() at v3.7.7","tags":["technical-description"]},{"url":"https://github.com/SIPp/sipp","tags":["product"]},{"name":"VulnCheck Advisory: SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/sipp-through-3.7.7-buffer-overflow-via-sip-to-header-tag"}],"credits":[{"lang":"en","value":"Tristan Madani","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-14T17:06:10.559977Z","id":"CVE-2026-90778","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-14T18:14:54.381Z"}}]}}