Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

signalwire — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting signalwire. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SignalWire provides cloud communication APIs for voice, video, and messaging services. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and authentication flaws. The platform has faced security incidents, including a 2022 vulnerability (CVE-2022-22963) allowing RCE via Spring Framework flaws. While SignalWire has patched these issues, the presence of multiple CVEs indicates ongoing security challenges in its communication infrastructure. Organizations should implement strict access controls and regular security assessments when integrating these services into their environments.

Found 17 results / 18 Clear Filters
Top products by signalwire: freeswitch libks
CVE ID Title CVSS Severity Published
CVE-2026-49848 FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto` — freeswitch CWE-287 4.3 Medium 2026-06-09
CVE-2026-49847 FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON — freeswitch CWE-674 7.5 High 2026-06-09
CVE-2026-49843 FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto` — freeswitch CWE-287 5.3 Medium 2026-06-09
CVE-2026-49842 FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames — freeswitch CWE-400 7.5 High 2026-06-09
CVE-2026-49841 FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read — freeswitch CWE-122 9.8 Critical 2026-06-09
CVE-2026-49840 FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing — freeswitch CWE-20 9.1 Critical 2026-06-09
CVE-2026-49475 FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing — freeswitch CWE-20 7.5 High 2026-06-09
CVE-2026-49472 FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat — freeswitch CWE-116 5.3 Medium 2026-06-09
CVE-2026-45771 Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion — freeswitch CWE-776 7.5 High 2026-06-09
CVE-2023-51443 FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation — freeswitch CWE-703 7.5 High 2023-12-27
CVE-2023-40019 FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names — freeswitch CWE-770 7.5 High 2023-09-15
CVE-2023-40018 FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID — freeswitch CWE-787 7.5 High 2023-09-15
CVE-2021-41158 FreeSWITCH vulnerable to SIP digest leak for configured gateways — freeswitch CWE-200 5.8 Medium 2021-10-26
CVE-2021-41157 FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default — freeswitch CWE-287 5.3 Medium 2021-10-26
CVE-2021-41105 FreeSWITCH susceptible to Denial of Service via invalid SRTP packets — freeswitch CWE-20 7.5 High 2021-10-25
CVE-2021-41145 FreeSWITCH susceptible to Denial of Service via SIP flooding — freeswitch CWE-400 8.6 High 2021-10-25
CVE-2021-37624 FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing — freeswitch CWE-287 7.5 High 2021-10-25

This page lists every published CVE security advisory associated with signalwire. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.