CVE-2026-90779: Sipp

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

Affected products

  • Sipp Sipp: up to and including 3.7.7

Published 2026-09-13. Last modified 2026-09-23.