{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sngrep--1.8.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sngrep:sngrep:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-90558"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["sngrep (\u003c= 1.8.4)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","sip","networking"],"_cs_type":"advisory","_cs_vendors":["sngrep"],"content_html":"\u003cp\u003esngrep versions 1.8.4 and earlier contain a critical stack-based buffer overflow vulnerability (CVE-2026-90558) within its SIP attribute formatting routines. The vulnerability arises from inadequate boundary checks when parsing SIP headers, such as Call-ID or X-Call-ID, which are constrained to a 255-byte stack buffer. When an attacker sends a specially crafted SIP packet containing header values exceeding this limit, the application memory is corrupted during the rendering process. This flaw enables attackers to force a process crash, leading to a denial-of-service, or potentially overwrite return addresses to execute arbitrary code with the privileges of the sngrep process. Given that sngrep is frequently used in network monitoring environments to capture and analyze VoIP traffic, successful exploitation could facilitate remote code execution on sensitive network management infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for remote code execution or application crashes. This impacts network security and VoIP service providers utilizing sngrep for traffic analysis. If an attacker gains code execution, they could achieve persistence within the monitoring node, sniff additional traffic, or pivot into other network segments where the monitoring node is located.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of all sngrep installations to a version beyond 1.8.4 that includes the fix for CVE-2026-90558. Implement network-level ingress filtering to prevent unauthorized SIP traffic from reaching network monitoring infrastructure that is not intended to be exposed to external actors.\u003c/p\u003e\n","date_modified":"2026-09-12T19:21:24Z","date_published":"2026-09-12T19:21:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sngrep-buffer-overflow/","summary":"sngrep versions up to 1.8.4 are vulnerable to a stack-based buffer overflow in SIP header formatting routines, allowing attackers to trigger crashes or achieve remote code execution via malformed SIP packets.","title":"Stack-based Buffer Overflow in sngrep SIP Parsing","url":"https://feed.craftedsignal.io/briefs/2026-09-sngrep-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Sngrep (\u003c= 1.8.4)","version":"https://jsonfeed.org/version/1.1"}