Security Advisories: Core And Auth Module (2026-04-07)
Fred Posner via sr-users <[email protected]> Wed, 8 Apr 2026 15:31:31 -0400
| Newsgroups | gmane.comp.voip.ser |
|---|---|
| Message-ID | <[email protected]> |
The Kamailio SIP Server project has released two security advisories on April 7, 2026. You can find the details here: - CVE-2026-39863: Core – TCP Data Processing Vulnerability (high) https://github.com/kamailio/kamailio/security/advisories/GHSA-2wj4-f825-2h2f - CVE-2026-39864: Auth – Processing Vulnerability For Additional Authenticated User Identity Checks (moderate) https://github.com/kamailio/kamailio/security/advisories/GHSA-6m86-m342-g48m We strongly suggest updating your Kamailio installation to the latest stable version. The issues were found over the last few months and fixed quickly. The code related to these issues is a bit old, and we have not seen anyone exploit these vulnerabilities yet. But now that the CVE reports are out, there might be a higher chance of someone trying to use them. If you have any private thoughts about these advisories or want to report any new security problems, please reach out to security [at] lists.kamailio.org. Thanks for flying Kamailio! Regards, Fred Posner __________________________________________________________ Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected] To unsubscribe send an email to [email protected] Important: keep the mailing list in the recipients, do not reply only to the sender!