Browse all 18 CVE security advisories affecting signalwire. AI-powered Chinese analysis, POCs, and references for each vulnerability.
SignalWire provides cloud communication APIs for voice, video, and messaging services. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and authentication flaws. The platform has faced security incidents, including a 2022 vulnerability (CVE-2022-22963) allowing RCE via Spring Framework flaws. While SignalWire has patched these issues, the presence of multiple CVEs indicates ongoing security challenges in its communication infrastructure. Organizations should implement strict access controls and regular security assessments when integrating these services into their environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-49846 | libks has path traversal in kws HTTP parser via URI segment overflow — libks CWE-22 | 7.5 | High | 2026-09-11 |
This page lists every published CVE security advisory associated with signalwire. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.