Drachtio is a narrowly scoped open-source SIP server and telephony framework, with its vulnerability profile concentrating in the core drachtio-server product. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and recur through memory-safety and boundary-handling weakness classes, including improper null termination, off-by-one errors, out-of-bounds reads, and reachable assertions, reflecting the low-level C/C++ implementation typical of real-time communications infrastructure. Defenders deploying this server should prioritize patching and monitor updates closely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Drachtio over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45474CRITICAL drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request. | Nov 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-45909CRITICAL drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request. | Nov 26, 2022 | 9.1 | 30 | NO | NO |
CVE-2022-47517HIGH An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message | Dec 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-47516HIGH An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message | Dec 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-47515HIGH An issue was discovered in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a long message in a TCP request that leads to s | Dec 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-45473MEDIUM In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666. | Nov 18, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drachtio.
Media articles that mention a CVE ID that affects a product developed by Drachtio — matched by CVE ID, not by vendor name.