External risk intelligence

sngrep SIP Header Stack Buffer Overflow Leads to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90558

sngrep is a terminal-based tool used for monitoring, capturing, and debugging SIP traffic. While it processes network packets, it is typically used as an interactive, local utility by administrators for troubleshooting rather than as a permanent, public-facing network service or internet-exposed gateway.

Buffer Overflow

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in sngrep, a tool used for monitoring and debugging SIP traffic. The issue involves a stack buffer overflow that can be triggered by specially crafted network packets, potentially leading to crashes or the execution of arbitrary code. The main concern is confirming the relevance and exposure of this tool within your environment.

  • Malicious packets can crash tools or run code.
  • Understand if sngrep is in use.
  • Assess impact and needed response.

Attack Path

How an attacker could exploit the issue

An attacker could send specially crafted network packets containing overly long SIP header values, such as the Call-ID or X-Call-ID. When the sngrep program processes these malformed packets, the excessive data can overflow a buffer on the stack, potentially leading to a program crash or allowing the attacker to execute arbitrary code.

  • Network access to sngrep is required.
  • Malicious SIP packets with oversized headers.
  • Code execution or denial of service.

Live Threat

Current exploitation, exposure, and threat context

When sngrep processes SIP packets with header values exceeding a 255-byte buffer, stack buffer overflows could lead to crashes or the execution of arbitrary code. This may occur during packet parsing and rendering when attackers craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields.

  • SIP packet data integrity may be affected.
  • Malicious SIP packets could cause overflows.
  • Service crashes or arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The affected technology, sngrep, is a terminal-based tool for SIP traffic monitoring and debugging. Because it processes network packets, infrastructure and platform teams responsible for network services and system utilities are likely involved in identifying and managing its deployment. The first practical step is to locate all instances of sngrep, confirm their network accessibility and business criticality, identify the accountable system owners, and then plan remediation based on assessed risk.

  • Identify sngrep instances and owners.
  • Verify network reachability and business impact.
  • Plan remediation actions based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is sngrep?

sngrep is a terminal-based utility designed for real-time monitoring, capturing, and troubleshooting SIP (Session Initiation Protocol) traffic. It acts as a visual interface for network administrators to inspect signaling flows. Because it functions by actively parsing and rendering complex network packets in a console environment, it requires robust handling of the data formats defined within SIP headers.

What does CWE-121 mean for CVE-2026-90558?

This CVE involves a stack-based buffer overflow (CWE-121). In plain terms, the software reserves a fixed, limited amount of memory to hold specific SIP header information. If a packet contains data longer than this limit—specifically exceeding 255 bytes—the extra data spills over into adjacent memory on the stack. This can corrupt the program's execution flow, potentially causing it to crash or allowing an attacker to run their own unauthorized instructions.

How does an attacker trigger this buffer overflow?

An attacker triggers this by sending malformed SIP packets toward an active sngrep instance. The vulnerability occurs specifically when the tool parses header fields like Call-ID or X-Call-ID that are larger than the allocated 255-byte buffer. Notably, the vulnerability only manifests when the tool actively processes these oversized packets; it is not triggered by standard, compliant SIP traffic that adheres to expected length specifications.

Why is Halo Surface Signal labeling this as 'Possible'?

Halo Surface Signal flags this as 'Possible' because sngrep is generally used as an interactive, local troubleshooting tool by administrators rather than a permanent, internet-facing gateway. While the vulnerability is network-reachable if the tool is actively capturing traffic from an untrusted source, the actual risk depends on your specific deployment. If your instances are restricted to internal, authorized monitoring, the potential for unauthorized external access is lower.

How should I respond to this vulnerability?

Begin by auditing your infrastructure to identify all systems where sngrep is installed and currently in use. Once identified, determine the network reachability of these systems—specifically whether they are exposed to traffic from untrusted sources. Work with your system owners to assess the business necessity of these instances and plan for updates or configuration changes to mitigate the risk of processing malicious, oversized SIP packets.

References