CVE-2026-52023
PoC moderateUnauthenticated DoS in Kamailio ims_registrar_pcscf module (≤ 6.1.1)
Kamailio 6.1.1 and earlier contain a remotely exploitable denial-of-service flaw (CWE-400) in the ims_registrar_pcscf module, the component that implements the IMS P-CSCF registrar role. The bug is triggered by network input reaching the pcscf_save_pending/save_pending path and by security-agreement parsing in sec_agree.c:parse_sec_agree(), allowing an unauthenticated remote attacker to exhaust resources or crash the SIP proxy. Successful exploitation yields high availability impact (CVSS 3.1 7.5, AV:N/AC:L/PR:N/UI:N) with no confidentiality or integrity loss, meaning IMS/VoLTE registration service behind the affected P-CSCF can be disrupted. Only deployments running Kamailio as a P-CSCF with the ims_registrar_pcscf and security-agreement (sec_agree) functionality enabled are affected; Kamailio installations that do not load these IMS modules are not exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates the 30-day exploitation probability at roughly 0.3%.
What to do: Upgrade to a Kamailio release newer than 6.1.1 that includes the fix, prioritizing any system that loads the ims_registrar_pcscf or sec_agree modules. As interim mitigation, disable ims_registrar_pcscf if the P-CSCF role is not required, restrict access to the P-CSCF SIP ports to trusted IMS signaling peers, and monitor for worker crashes or unexpected restarts.
| Kamailio (open-source project) Kamailio (ims_registrar_pcscf module / P-CSCF role, sec_agree.c) | 6.1.1 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
- Vendors
- kamailio
- Products
- kamailio
- Weakness
- CWE-415, CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.