OpenSIPS disclosed CVE-2026-46334, a remotely triggerable denial-of-service flaw in SDP bandwidth-line parsing that affects versions prior to 3.6.6 and 4.0.0-rc1. A malformed session-level b= SDP line missing the required : delimiter can corrupt parsed bandwidth metadata, and if that corrupted SDP state is later cloned during dialog handling or QoS processing, an OpenSIPS worker process can crash. The issue is exploitable by an unauthenticated attacker in deployments that parse attacker-controlled SDP and use affected routing or module logic.
The fix was introduced through OpenSIPS commits that harden parser/sdp/sdp_helpr_funcs.c by rejecting malformed bandwidth lines, adding boundary checks, and preventing unsafe access when b= appears at the start of the buffer or lacks a separator. The patched code logs an error and returns failure for invalid SDP bandwidth encoding, closing the crash path in both the 3.6 and 4.0.0 code lines. The vulnerability is mapped to CWE-20 and CWE-476 and carries high availability impact.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record states that security-advisories@github.com received the advisory for CVE-2026-46334 on August 5, 2026. The issue describes a remotely triggerable denial-of-service flaw in OpenSIPS SDP bandwidth parsing affecting versions before 3.6.6 and 4.0.0-rc1.
OpenSIPS committed code changes to reject malformed SDP "b=" bandwidth lines in the SDP parser, adding validation for missing colon separators and other unsafe parsing conditions. The fixes were committed in both the 3.6 and 4.0 code lines and are referenced as the remediation for CVE-2026-46334.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.