← Terug naar overzicht

A vulnerability has been identified in Kamailio versions up to 5.5.0 and 6.0.7 affecting the get_4bytes function in the AVP Handler component (src/modules/ims_registrar_scscf/cxdx_avp.c). The flaw can lead to an out-of-bounds read condition that can be triggered remotely. A public exploit has been disclosed, increasing the risk of active exploitation. A patch (abb5d60af6eefbd367bf6588c5589566b090e272) has been released to address the issue. The vendor notes that version 5.5.0 is no longer maintained, urging users to upgrade. Administrators running affected versions are strongly advised to apply the patch immediately. The vulnerability is tracked as CVE-2026-82608 and is listed on NVD and VulDB.

Affected products

  • Kamailio 5.5.0
  • Kamailio 6.0.7

Related CVE's

  • CVE-2026-82608

Categories

  • Network Infrastructure