OpenSIPS disclosed CVE-2026-45809, a high-severity denial-of-service flaw in watcherinfo XML generation that can let a remote attacker crash a worker process. The bug affects versions prior to 3.6.6 and 4.0.0-rc1 and is triggered when an attacker sends a SUBSCRIBE presence request with an excessively long From URI, creating an oversized watcher entry that later causes a stack buffer overflow during presence.winfo XML generation. The issue is classified as CWE-121 and impacts deployments that expose handle_subscribe() with watcherinfo enabled through the presence and presence_xml modules.
OpenSIPS maintainers patched the flaw in commits c5970d3ee25b457ad2d78fe6e9662a12dae577cd and dd86461b71ff4a4f5194205896ae5f48f144240d, replacing a fixed 200-byte stack buffer with a length-aware XML API call. The fix changes watcher URI handling so XML nodes are created without inline content and then populated using xmlNodeSetContentLen, preventing long URIs from overflowing the buffer during winfo processing. Organizations running exposed OpenSIPS presence services are advised to upgrade to the fixed releases.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-45809 was newly received by security-advisories@github.com on August 5, 2026. The advisory describes a denial-of-service flaw in OpenSIPS watcherinfo XML generation affecting versions before 3.6.6 and 4.0.0-rc1.
On May 13, 2026, OpenSIPS committed fixes for an XML overflow caused by long watcher URIs in presence.winfo generation. The patches removed a fixed-size 200-byte stack buffer in create_winfo_xml and switched to a length-aware XML API in both the 3.6 and 4.0 code lines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.