DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-58268: CVE-2026-58268: Denial of Service via Uncontrolled Memory Allocation in emiago/sipgo Stream Parser

CVE-2026-58268: Denial of Service via Uncontrolled Memory Allocation in emiago/sipgo Stream Parser

Vulnerability ID: CVE-2026-58268
CVSS Score: 7.5
Published: 2026-09-22

A high-severity denial of service vulnerability exists in the emiago/sipgo Go library when parsing stream-based SIP messages. The stream parser fails to validate declared Content-Length header sizes before initiating memory allocations, allowing remote, unauthenticated attackers to trigger process memory exhaustion and application crashes.

TL;DR

Unauthenticated remote attackers can crash sipgo-based services by transmitting a crafted SIP stream with an excessively large Content-Length header, causing the Go application to exhaust memory and terminate.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-789
  • Attack Vector: Network (AV:N)
  • CVSS Score: 7.5 (High)
  • Exploit Status: Proof-of-Concept
  • CISA KEV Status: Not Listed
  • Remediation Status: Patched in v1.4.1

Affected Systems

  • Applications utilizing emiago/sipgo prior to version 1.4.1
  • SIP gatekeepers, routers, and endpoints listening on TCP/TLS/WS/WSS transports using sipgo
  • sipgo: < 1.4.1 (Fixed in: 1.4.1)

Code Analysis

Commit: a7be60a

fix: prevent DOS allocation on stream parser with large Content length

Mitigation Strategies

  • Upgrade library dependencies to version 1.4.1 or higher.
  • Enforce explicit limit configurations via MaxMessageLength.
  • Filter excessively large Content-Length values at the network boundary.

Remediation Steps:

  1. Open a terminal in the root directory of your Go application.
  2. Execute the update command: go get github.com/emiago/sipgo@v1.4.1
  3. Clean up unnecessary module paths by executing: go mod tidy
  4. Rebuild and deploy the updated service binary.

References


Read the full report for CVE-2026-58268 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)