CVE-2020-27507: Kamailio
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
Affected products
- Kamailio Kamailio: before 5.5.0 (fixed in 5.5.0)
Published 2023-03-15. Last modified 2026-06-17.