Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

signalwire — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting signalwire. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SignalWire provides cloud communication APIs for voice, video, and messaging services. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and authentication flaws. The platform has faced security incidents, including a 2022 vulnerability (CVE-2022-22963) allowing RCE via Spring Framework flaws. While SignalWire has patched these issues, the presence of multiple CVEs indicates ongoing security challenges in its communication infrastructure. Organizations should implement strict access controls and regular security assessments when integrating these services into their environments.

Found 17 results / 17Clear Filters
Top products by signalwire: freeswitch
CVE IDTitleCVSSSeverityPublished
CVE-2026-49848 FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto` — freeswitchCWE-287 4.3 Medium2026-06-09
CVE-2026-49847 FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON — freeswitchCWE-674 7.5 High2026-06-09
CVE-2026-49843 FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto` — freeswitchCWE-287 5.3 Medium2026-06-09
CVE-2026-49842 FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames — freeswitchCWE-400 7.5 High2026-06-09
CVE-2026-49841 FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read — freeswitchCWE-122 9.8 Critical2026-06-09
CVE-2026-49840 FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing — freeswitchCWE-20 9.1 Critical2026-06-09
CVE-2026-49475 FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing — freeswitchCWE-20 7.5 High2026-06-09
CVE-2026-49472 FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat — freeswitchCWE-116 5.3 Medium2026-06-09
CVE-2026-45771 Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion — freeswitchCWE-776 7.5 High2026-06-09
CVE-2023-51443 FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation — freeswitchCWE-703 7.5 High2023-12-27
CVE-2023-40019 FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names — freeswitchCWE-770 7.5 High2023-09-15
CVE-2023-40018 FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID — freeswitchCWE-787 7.5 High2023-09-15
CVE-2021-41158 FreeSWITCH vulnerable to SIP digest leak for configured gateways — freeswitchCWE-200 5.8 Medium2021-10-26
CVE-2021-41157 FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default — freeswitchCWE-287 5.3 Medium2021-10-26
CVE-2021-41105 FreeSWITCH susceptible to Denial of Service via invalid SRTP packets — freeswitchCWE-20 7.5 High2021-10-25
CVE-2021-41145 FreeSWITCH susceptible to Denial of Service via SIP flooding — freeswitchCWE-400 8.6 High2021-10-25
CVE-2021-37624 FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing — freeswitchCWE-287 7.5 High2021-10-25

This page lists every published CVE security advisory associated with signalwire. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.