Executive brief
FreeSWITCH is a software-based telecommunications platform used to handle voice and video calls. A security flaw in its communication module allows an unauthenticated attacker to forcibly disconnect legitimate users and drop their active calls if the attacker knows the user's session ID. While this does not allow the attacker to steal data or take over accounts, it can be used to disrupt telecommunications services and cause targeted outages.
Technical details
A vulnerability exists in FreeSWITCH's mod_verto module where the JSON-RPC handler binds a connection to a client-supplied 'sessid' on the very first frame, prior to the authentication gate. This binding process inserts the connection into a global session hash; if an attacker provides a 'sessid' that is already in use, the system triggers a key collision and 'punts' the original occupant. This results in the legitimate client's calls being detached and their WebSocket connection being closed. While the attacker cannot bypass authentication to perform further actions, they can effectively perform a targeted Denial of Service (DoS) if they obtain a valid session UUID through side channels. The issue is resolved in version 1.11.1 by moving the session binding logic until after successful authentication.
Affected products
- SignalWire FreeSWITCH < 1.11.1
Timeline
- 2026-05-26: patched: Version 1.11.1 released
- 2026-06-03: advisory: GitHub Security Advisory published
- 2026-06-09: disclosed: CVE published to NVD