CVE-2026-39863: Kamailio Core: TCP Data Processing Vulnerability
Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39863?
CVE-2026-39863 has a high severity as it allows remote attackers to cause a denial of service through a process crash.
How do I fix CVE-2026-39863?
To mitigate CVE-2026-39863, upgrade Kamailio to version 6.1.1, 6.0.6, or 5.8.8 or higher.
What versions of Kamailio are affected by CVE-2026-39863?
CVE-2026-39863 affects Kamailio versions prior to 6.1.1, 6.0.6, and 5.8.8.
What type of vulnerability is CVE-2026-39863?
CVE-2026-39863 is an out-of-bounds access vulnerability in the core of Kamailio.
Can CVE-2026-39863 be exploited remotely?
Yes, CVE-2026-39863 can be exploited remotely by attackers to cause denial of service.