CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-90558 — sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attri...
·Source: NIST NVD
Updated:
Executive Summary
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.
Analysis
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering. CVSS Score: 9.8. Published: 2026-09-12T18:16:44.587.