---
id: CVE-2026-90778
title: >-
  SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag()
  function when processing SIP To headers with tag parameters of 2049 bytes or
  more
summary: >-
  SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag()
  function when processing SIP To headers with tag parameters of 2049 bytes or
  more. Unauthenticated remote attackers can send crafted SIP messages with
  oversize…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: SIPp
product: sipp
affected:
  - sipp <= 3.7.7
published: '2026-09-13'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:47.527'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90778'
references:
  - url: 'https://github.com/SIPp/sipp'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/SIPp/sipp/blob/v3.7.7/src/sip_parser.cpp#L76-L113'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/SIPp/sipp/commit/ddf22d1a54e0396b2e18ebaf4cf5a3fa860e5da4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/SIPp/sipp/pull/879'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/sipp-through-3.7.7-buffer-overflow-via-sip-to-header-tag
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90778.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90778'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90778'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00857
epssPercentile: 0.56672
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T17:06:10.559977Z'
ingestedAt: '2026-09-14T15:23:07.470Z'
---

## Overview

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90778.json)
