Threat Advisory

SIPGO Flaw Lets Attackers Cause DoS via Unvalidated Content-Length

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version range not explicitly stated. These vulnerabilities pose a moderate to high risk of denial-of-service attacks.

CVE-2026-58268 (CVSS 7.5 — High): A denial-of-service vulnerability exists via unvalidated Content-Length in the stream parser. An attacker can exploit this by sending a malicious request.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version range not explicitly stated. These vulnerabilities pose a moderate to high risk of denial-of-service attacks.

CVE-2026-58268 (CVSS 7.5 — High): A denial-of-service vulnerability exists via unvalidated Content-Length in the stream parser. An attacker can exploit this by sending a malicious request.[emaillocker id="1283"]

CVE-2026-77322: A denial-of-service vulnerability exists via unvalidated WebSocket frame length.

RECOMMENDATION:

We recommend you to update sipgo to version 1.4.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu