CVE-2026-52022
PoC moderateUnauthenticated Remote DoS in Kamailio IMS P-CSCF Registration Handling
CVE-2026-52022 is a remotely exploitable denial-of-service flaw (CWE-400, uncontrolled resource consumption) in Kamailio, the open-source SIP server, affecting versions 6.1.1 and earlier. An unauthenticated network attacker can trigger the vulnerability through the IMS P-CSCF registration handling components, exhausting resources and taking the service down. The impact is availability-only (CVSS 3.1 7.5 with Network vector, no privileges or user interaction required); there is no indication of code execution or data exposure. Only Kamailio deployments actually running the IMS P-CSCF role — typically carrier VoLTE/IMS infrastructure, operator test labs, and related telecom setups — are affected. Exploitation has not been observed in the wild: it is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days, and one public proof-of-concept issue reference is available.
What to do: Inventory Kamailio deployments and determine whether the IMS P-CSCF registration handling components are in use; systems not using that role are not affected. Upgrade to a patched Kamailio release as soon as one is published (anything later than 6.1.1 once fixes ship), and consult the referenced GitHub issue (kamailio/kamailio#4670) for reproduction details. Until patching, restrict access to P-CSCF/REGISTER-facing SIP ports to trusted carrier networks and apply rate limiting on unauthenticated REGISTER traffic to blunt DoS attempts.
| Kamailio | 6.1.1 and all earlier versions (flaw specific to the IMS P-CSCF registration handling components) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
- Vendors
- kamailio
- Products
- kamailio
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.