CVE-2026-0710

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. This vulnerability, a NULL pointer dereference, can cause the application to crash, leading to a denial of service. Under specific conditions, it may also allow an attacker to execute unauthorized code, compromising the system's integrity and availability.

Published 2026-01-23. Last modified 2026-06-17.