High severity7.5NVD Advisory· Published Apr 8, 2026· Updated Apr 15, 2026
CVE-2026-39863
CVE-2026-39863
Description
Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/kamailio/kamailio/security/advisories/GHSA-2wj4-f825-2h2fnvdVendor Advisory
News mentions
0No linked articles in our index yet.