« Volver al listado

CVE-2026-39863

Estado: AnalizadaAlta (7.5)—

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de acceso remoto sin autenticación (PR:N) ni interacción (UI:N) en servidor SIP expuesto. El OOB (CWE-119) causa crash del proceso (DoS), impactando disponibilidad.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-39863",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-39863",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-09T13:52:31.304154Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "kamailio",
          "product": "kamailio",
          "versions": [
            {
              "status": "affected",
              "version": "< 5.8.8"
            },
            {
              "status": "affected",
              "version": ">= 6.0.0, < 6.0.6"
            },
            {
              "status": "affected",
              "version": ">= 6.1.0, < 6.1.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-08T20:16:26.550",
  "references": [
    {
      "url": "https://github.com/kamailio/kamailio/security/advisories/GHSA-2wj4-f825-2h2f",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8."
    },
    {
      "lang": "es",
      "value": "Kamailio es una implementación de código abierto de un Servidor de Señalización SIP. Antes de 6.1.1, 6.0.6 y 5.8.8, un acceso fuera de límites en el núcleo de Kamailio (anteriormente OpenSER y SER) permite a atacantes remotos causar una denegación de servicio (caída del proceso) mediante un paquete de datos especialmente diseñado enviado por TCP. El problema afecta a las instancias de Kamailio que tienen oyentes TCP o TLS. Esta vulnerabilidad está corregida en 5.1.1, 6.0.6 y 5.8.8."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B40580E-F077-4ECD-A293-C5376753A14F",
              "versionEndExcluding": "5.8.8"
            },
            {
              "criteria": "cpe:2.3:a:kamailio:kamailio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEF7235B-DFA7-4445-81F2-490609E9FCD6",
              "versionEndExcluding": "6.0.6",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:kamailio:kamailio:6.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A33A90A-7EC3-407F-BD7B-E13A2617B59D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}