CVE-2026-58268
7.5 HIGHpublic exploit availablePublished 2026-09-22 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is enforced. An unauthenticated peer can send a stream-transport message over TCP, TLS, WS, or WSS with an oversized declared length, causing excessive memory allocation and denial of service before the body is read. This issue is fixed in version 1.4.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-789
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-102809PoC
- MEDIUMCVE-2026-102820PoC
- MEDIUMCVE-2026-15337PoC
- HIGHCVE-2026-47321
- UNSCOREDCVE-2026-58067
- HIGHCVE-2026-59991PoC
- HIGHCVE-2026-61485
- MEDIUMCVE-2026-62370PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.