CVE-2026-58268: Denial of Service via Uncontrolled Memory Allocation in emiago/sipgo Stream Parser
Vulnerability ID: CVE-2026-58268
CVSS Score: 7.5
Published: 2026-09-22
A high-severity denial of service vulnerability exists in the emiago/sipgo Go library when parsing stream-based SIP messages. The stream parser fails to validate declared Content-Length header sizes before initiating memory allocations, allowing remote, unauthenticated attackers to trigger process memory exhaustion and application crashes.
TL;DR
Unauthenticated remote attackers can crash sipgo-based services by transmitting a crafted SIP stream with an excessively large Content-Length header, causing the Go application to exhaust memory and terminate.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-789
- Attack Vector: Network (AV:N)
- CVSS Score: 7.5 (High)
- Exploit Status: Proof-of-Concept
- CISA KEV Status: Not Listed
- Remediation Status: Patched in v1.4.1
Affected Systems
- Applications utilizing emiago/sipgo prior to version 1.4.1
- SIP gatekeepers, routers, and endpoints listening on TCP/TLS/WS/WSS transports using sipgo
-
sipgo: < 1.4.1 (Fixed in:
1.4.1)
Code Analysis
Commit: a7be60a
fix: prevent DOS allocation on stream parser with large Content length
Mitigation Strategies
- Upgrade library dependencies to version 1.4.1 or higher.
- Enforce explicit limit configurations via MaxMessageLength.
- Filter excessively large Content-Length values at the network boundary.
Remediation Steps:
- Open a terminal in the root directory of your Go application.
- Execute the update command: go get github.com/emiago/sipgo@v1.4.1
- Clean up unnecessary module paths by executing: go mod tidy
- Rebuild and deploy the updated service binary.
References
- GitHub Security Advisory GHSA-pg59-5vwg-4jxq
- Fix Commit a7be60a0
- sipgo v1.4.1 Release Notes
- CVE-2026-58268 Record
Read the full report for CVE-2026-58268 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)