CVE-2026-39863

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
08/04/2026
Last modified:
15/04/2026

Description

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:* 5.8.8 (excluding)
cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.6 (excluding)
cpe:2.3:a:kamailio:kamailio:6.1.0:*:*:*:*:*:*:*