CVE-2026-77322
- EPSS 0.52%
- Veröffentlicht 22.09.2026 19:52:12
- Zuletzt bearbeitet 23.09.2026 18:12:04
SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before Parse...
CVE-2026-58268
- EPSS 0.61%
- Veröffentlicht 22.09.2026 19:49:09
- Zuletzt bearbeitet 23.09.2026 18:12:04
SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is enforced. An...
CVE-2025-68274
- EPSS 0.55%
- Veröffentlicht 16.12.2025 22:02:55
- Zuletzt bearbeitet 05.03.2026 19:52:09
SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alpha-1, a nil pointer dereference vulnerability is in the SIPGO library's `NewResponseFromRequest` function that affects all normal ...