OpenSIPS is a widely deployed open-source Session Initiation Protocol (SIP) server that serves as infrastructure for VoIP networks and telecommunications platforms. The vendor's vulnerability profile centers on its core product and clusters around network-protocol parsing and resource-management weaknesses, including improper input validation, integer overflows, resource-exhaustion conditions, and infinite-loop flaws that are characteristic of message-handling code under untrusted network input. Defenders should prioritize patches for this telecommunications infrastructure component, particularly in internet-exposed deployments; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensips over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25554MEDIUM OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_authorize() function in modules/auth | Feb 25, 2026 | 6.5 | 26 | NO | NO |
CVE-2023-27596HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crashes when a malformed SDP body is sent multiple times to an Op | Mar 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-28099HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_list()` is used with an invalid IP address string (`NULL` is | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-28097HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SIP message containing a large _Content-Length_ value and a sp | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-28096HIGH OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. The memory leak was detecte | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-28095HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potential issue in `msg_translator.c:2628` which might lead to a ser | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-27601HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-27600HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-27599HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the function `append_hf` handles a SIP message with a malformed To he | Mar 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-27598HIGH OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIPS triggers a segmentation fault | Mar 15, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensips.
Media articles that mention a CVE ID that affects a product developed by Opensips — matched by CVE ID, not by vendor name.