---
id: CVE-2026-90780
title: >-
  SIPp through 3.7.7 contains a buffer overflow vulnerability in the
  get_header() function in src/sip_parser.cpp when processing SIP messages with
  header content exceeding 20,490 bytes
summary: >-
  SIPp through 3.7.7 contains a buffer overflow vulnerability in the
  get_header() function in src/sip_parser.cpp when processing SIP messages with
  header content exceeding 20,490 bytes. Unauthenticated remote attackers can
  send crafted SIP…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: SIPp
product: sipp
affected:
  - sipp <= 3.7.7
published: '2026-09-13'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:44.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90780'
references:
  - url: 'https://github.com/SIPp/sipp'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/SIPp/sipp/blob/v3.7.7/src/sip_parser.cpp#L164-L227'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/SIPp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232
    label: disclosure@vulncheck.com
  - url: 'https://github.com/SIPp/sipp/pull/881'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/sipp-through-3.7.7-buffer-overflow-via-oversized-sip-header-content
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90780.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90780'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90780'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00633
epssPercentile: 0.48998
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-20T00:11:10.302315Z'
ingestedAt: '2026-09-14T15:23:07.470Z'
---

## Overview

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90780.json)
