CVE-2026-52023: Kamailio

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()

Affected products

  • Kamailio Kamailio: up to and including 6.1.1

Published 2026-09-01. Last modified 2026-09-15.