CVE-2022-45909
CWE-125Published: November 26, 2022· Updated: Jun 17, 2026
Official Description
drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
Risk Analysis
The drachtio-server is vulnerable to a heap-based buffer over-read when processing long Request-URI strings in INVITE requests. This critical flaw could lead to unauthorized data access or service disruption.
There is no public exploit known, and it is not in the CISA KEV. The vulnerability is remotely exploitable with low attack complexity.
Users should update to drachtio-server version 0.8.19 or later to address the buffer over-read vulnerability.
Technical Analysis
CVE-2022-45909 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
A successful exploit results in complete confidentiality breach (data exposure), availability disruption (denial of service), with a CVSS base score of 9.1.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
Official Patches & Advisories
All References (6)
Quick Facts
Related CVEs (CWE-125)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2022-45909 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts