A vulnerability has been found in OpenSIPS up to 3.6.5 and classified as very critical. The impacted element is the function
construct_uri of the component URI Construction. The manipulation of the argument Username leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2026-45537. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.