Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

freeswitch — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in freeswitch, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the product FreeSWITCH, specifically tracking software weaknesses within the VoIP server and media gateway ecosystem. It collects publicly disclosed security flaws, including memory corruption, remote code execution, and authentication bypasses, covering advisories from early release cycles through recent maintenance patches. Readers can track vendor-issued security advisories, understand specific weakness classes affecting signaling protocols like SIP and RTP, and review the product’s complete vulnerability history to assess cumulative risk. The dataset focuses on technical defects rather than marketing claims, providing a factual record of security issues documented across multiple versions. Users can filter entries by vulnerability type or severity to identify patterns in the product’s security posture over time. This aggregation supports threat modeling by highlighting recurring weakness categories, such as buffer overflows in media stream processing or session handling. The collection spans from initial open-source releases to the latest stable builds, ensuring comprehensive coverage of historical and current security concerns.

Vendor: signalwire

CVE ID Title CVSS Severity Published
CVE-2026-49848 FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto` CWE-287 4.3 Medium 2026-06-09
CVE-2026-49847 FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON CWE-674 7.5 High 2026-06-09
CVE-2026-49843 FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto` CWE-287 5.3 Medium 2026-06-09
CVE-2026-49842 FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames CWE-400 7.5 High 2026-06-09
CVE-2026-49841 FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read CWE-122 9.8 Critical 2026-06-09
CVE-2026-49840 FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing CWE-20 9.1 Critical 2026-06-09
CVE-2026-49475 FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing CWE-20 7.5 High 2026-06-09
CVE-2026-49472 FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat CWE-116 5.3 Medium 2026-06-09
CVE-2026-45771 Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion CWE-776 7.5 High 2026-06-09
CVE-2023-51443 FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation CWE-703 7.5 High 2023-12-27
CVE-2023-40019 FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names CWE-770 7.5 High 2023-09-15
CVE-2023-40018 FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID CWE-787 7.5 High 2023-09-15
CVE-2021-41158 FreeSWITCH vulnerable to SIP digest leak for configured gateways CWE-200 5.8 Medium 2021-10-26
CVE-2021-41157 FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default CWE-287 5.3 Medium 2021-10-26
CVE-2021-41105 FreeSWITCH susceptible to Denial of Service via invalid SRTP packets CWE-20 7.5 High 2021-10-25
CVE-2021-41145 FreeSWITCH susceptible to Denial of Service via SIP flooding CWE-400 8.6 High 2021-10-25
CVE-2021-37624 FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing CWE-287 7.5 High 2021-10-25

All 17 known CVE vulnerabilities affecting freeswitch with full Chinese analysis, references, and POCs where available.