SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-90779 is a stack buffer overflow vulnerability in SIPp versions through 3.7.7 that occurs when the createAuthHeader() function processes SIP authentication challenges containing oversized algorithm parameters. An attacker controlling a malicious SIP server can craft specially formed 401 or 407 authentication challenge responses that cause stack memory corruption, leading to denial of service through process crashes. This affects any organization or endpoint using SIPp for SIP protocol testing, VoIP communications, or SIP-based automation, making it relevant to telecommunications infrastructure, contact centers, and unified communications environments where SIPp is deployed.
While this CVE does not map to specific MITRE ATT&CK techniques, Casky's extended reasoning capabilities would identify the underlying attack pattern as a form of network-based exploitation and resource exhaustion. Practitioners using Casky would observe findings related to CWE-121 (stack-based buffer overflow) detection during protocol analysis, flagging anomalous SIP message structures with parameter length violations that exceed expected bounds. The platform's 754 mapped security skills would enable detection of malformed authentication headers through protocol validation checks, allowing teams to identify crafted SIP challenges before they reach vulnerable createAuthHeader() functions—effectively shifting from reactive crash analysis to proactive message validation and threat prevention.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90779. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation