Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kamailio

First CVE: Apr 11, 2016Active for: 10 yearsTotal CVEs: 15
55.8
VTI Score
TOP TARGET

Kamailio is a widely deployed open-source SIP (Session Initiation Protocol) server and VoIP platform that sits at the core of telecommunications and real-time communication infrastructure, making it a prominent target in call-routing and media-handling networks. Its vulnerabilities skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including buffer overflows, out-of-bounds writes, NULL-pointer dereferences, and improper memory management that are characteristic of a large, signal-processing C codebase. The vendor's disclosures frequently acquire public exploit tooling, reflecting the accessibility and value of internet-exposed VoIP infrastructure to attackers; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kamailio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2016
10 years ago
Most Recent CVE
Apr 8, 2026
107 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-2385CRITICAL
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a deni
Apr 11, 20169.860NOYES
CVE-2018-14767CRITICAL
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing
Jul 31, 20189.844NONO
CVE-2018-8828CRITICAL
A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message with a malformed branch or From ta
Mar 20, 20189.844NONO
CVE-2018-16657CRITICAL
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input vali
Sep 7, 20189.831NONO
CVE-2013-7426CRITICAL
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.
Aug 29, 20179.831NONO
CVE-2020-27507CRITICAL
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have uns
Mar 15, 20239.830NONO
CVE-2026-39863HIGH
Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) al
Apr 8, 20267.526NONO
CVE-2025-12205HIGH
A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Configuration File Handler. The ma
Oct 27, 20257.824NONO
CVE-2025-12204HIGH
A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rvalue.c of the component Configuration File Handler. The mani
Oct 27, 20257.823NONO
CVE-2025-12207MEDIUM
A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to nu
Oct 27, 20255.520NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
27%
33%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (40.0%)
Network9 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (46.7%)
High1 (6.7%)
None7 (46.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kamailio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kamailio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kamailio's Products

View all 3 CNAs →

Top CWEs