ZeroHour

CVE-2026-52023

PoC moderate

Unauthenticated DoS in Kamailio ims_registrar_pcscf module (≤ 6.1.1)

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
AI analysis

Kamailio 6.1.1 and earlier contain a remotely exploitable denial-of-service flaw (CWE-400) in the ims_registrar_pcscf module, the component that implements the IMS P-CSCF registrar role. The bug is triggered by network input reaching the pcscf_save_pending/save_pending path and by security-agreement parsing in sec_agree.c:parse_sec_agree(), allowing an unauthenticated remote attacker to exhaust resources or crash the SIP proxy. Successful exploitation yields high availability impact (CVSS 3.1 7.5, AV:N/AC:L/PR:N/UI:N) with no confidentiality or integrity loss, meaning IMS/VoLTE registration service behind the affected P-CSCF can be disrupted. Only deployments running Kamailio as a P-CSCF with the ims_registrar_pcscf and security-agreement (sec_agree) functionality enabled are affected; Kamailio installations that do not load these IMS modules are not exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates the 30-day exploitation probability at roughly 0.3%.

What to do: Upgrade to a Kamailio release newer than 6.1.1 that includes the fix, prioritizing any system that loads the ims_registrar_pcscf or sec_agree modules. As interim mitigation, disable ims_registrar_pcscf if the P-CSCF role is not required, restrict access to the P-CSCF SIP ports to trusted IMS signaling peers, and monitor for worker crashes or unexpected restarts.

Affected
Kamailio (open-source project) Kamailio (ims_registrar_pcscf module / P-CSCF role, sec_agree.c)6.1.1 and earlier
Estimated exposure
moderatelikely on the order of thousands of P-CSCF instances worldwide (estimate; no public install counts) — Kamailio is one of the most widely deployed open-source SIP servers, but only the specialized subset of deployments running IMS/P-CSCF configurations loads ims_registrar_pcscf, and these typically sit inside carrier networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()

Vendors
kamailio
Products
kamailio
Weakness
CWE-415, CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.