{"id":"CVE-2026-82608","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82608","summary":"A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler.…","details":"A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that \"[v]ersion 5.5.0 is old and not maintained anymore.\"","published":"2026-08-31T03:16:43.293","modified":"2026-08-31T03:16:43.293","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/Kamailio/Kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272","label":"Kamailio/Kamailio@abb5d60"},"references":[{"type":"WEB","url":"https://github.com/Kamailio/Kamailio/commit/abb5d60af6eefbd367bf6588c5589566b090e272"},{"type":"WEB","url":"https://github.com/Kamailio/Kamailio/pull/4823"},{"type":"WEB","url":"https://github.com/kamailio/kamailio/"},{"type":"WEB","url":"https://github.com/kamailio/kamailio/issues/4816"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-82608"},{"type":"WEB","url":"https://vuldb.com/submit/892903"},{"type":"WEB","url":"https://vuldb.com/vuln/397109"},{"type":"WEB","url":"https://vuldb.com/vuln/397109/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-31T03:16:43.293"}}