CVE-2026-45537
OpenSIPS URI Construction Buffer Overflow in construct_uri() Function
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
OpenSIPS, a SIP server, contains a buffer overflow vulnerability in its `construct_uri()` function. Attackers can exploit this by sending crafted requests to overwrite memory, potentially altering server routing behavior and disrupting services. This issue affects servers that are externally reachable.