PT-2026-31443 · Kamailio · Kamailio

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-39864

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kamailio versions prior to 6.0.5 and 5.8.7
Description Kamailio, an open source SIP Signaling Server, contains a flaw in the auth module. A specially crafted SIP packet can trigger an out-of-bounds read, leading to a denial of service (process crash) if a successful user authentication occurs without a database backend, followed by further user identity checks.
Recommendations Update to version 6.0.5 or 5.8.7

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-39864

Affected Products

Kamailio