{"schema_version":1,"title":"SignalWire Freeswitch vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in SignalWire Freeswitch: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-49848, was published on 9 June 2026.","url":"https://junglewise.ai/threats/technologies/freeswitch","json_url":"https://junglewise.ai/threats/technologies/freeswitch.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/freeswitch","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":9,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":9},"latest":[{"cve":"CVE-2026-49848","cvss":4.3,"slug":"cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth","title":"FreeSWITCH mod_verto userVariables injection in check_auth","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.46+00:00","url":"https://junglewise.ai/threats/cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth"},{"cve":"CVE-2026-49847","cvss":7.5,"slug":"cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto","title":"FreeSWITCH stack overflow in cJSON parser via mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.32+00:00","url":"https://junglewise.ai/threats/cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto"},{"cve":"CVE-2026-49843","cvss":5.3,"slug":"cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session","title":"FreeSWITCH improper authentication in mod_verto allows session eviction","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.17+00:00","url":"https://junglewise.ai/threats/cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session"},{"cve":"CVE-2026-49842","cvss":7.5,"slug":"cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto","title":"SignalWire FreeSWITCH bandwidth amplification in mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.017+00:00","url":"https://junglewise.ai/threats/cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto"},{"cve":"CVE-2026-49841","cvss":9.8,"slug":"cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post","title":"SignalWire FreeSWITCH heap overflow in mod_verto HTTP POST handler","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.87+00:00","url":"https://junglewise.ai/threats/cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post"},{"cve":"CVE-2026-49840","cvss":9.1,"slug":"cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content","title":"SignalWire FreeSWITCH heap buffer overflow in libesl Content-Length parsing","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.703+00:00","url":"https://junglewise.ai/threats/cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content"},{"cve":"CVE-2026-49475","cvss":7.5,"slug":"cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser","title":"SignalWire FreeSWITCH out-of-bounds memory access in STUN parser","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:47.39+00:00","url":"https://junglewise.ai/threats/cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser"},{"cve":"CVE-2026-49472","cvss":5.3,"slug":"cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone","title":"FreeSWITCH denial of service in XML-RPC via libexpat clone","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:47.243+00:00","url":"https://junglewise.ai/threats/cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone"},{"cve":"CVE-2026-45771","cvss":7.5,"slug":"cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish","title":"FreeSWITCH XML entity expansion denial of service in SIP PUBLISH","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:33.303+00:00","url":"https://junglewise.ai/threats/cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"SignalWire Freeswitch","slug":"freeswitch","vendor":{"name":"SignalWire","slug":"signalwire","url":"https://junglewise.ai/threats/vendors/signalwire"},"aliases":[],"category":"telephony-server","homepage":"https://freeswitch.org/","repo_url":"https://github.com/signalwire/freeswitch","description":"FreeSWITCH is a scalable, open-source cross-platform telephony platform designed to route and interconnect popular communication protocols using audio, video, text, or any other form of media.","url":"https://junglewise.ai/threats/technologies/freeswitch"},"most_severe":[{"cve":"CVE-2026-49841","cvss":9.8,"slug":"cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post","title":"SignalWire FreeSWITCH heap overflow in mod_verto HTTP POST handler","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.87+00:00","url":"https://junglewise.ai/threats/cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post"},{"cve":"CVE-2026-49840","cvss":9.1,"slug":"cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content","title":"SignalWire FreeSWITCH heap buffer overflow in libesl Content-Length parsing","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.703+00:00","url":"https://junglewise.ai/threats/cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content"},{"cve":"CVE-2026-49847","cvss":7.5,"slug":"cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto","title":"FreeSWITCH stack overflow in cJSON parser via mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.32+00:00","url":"https://junglewise.ai/threats/cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto"},{"cve":"CVE-2026-49842","cvss":7.5,"slug":"cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto","title":"SignalWire FreeSWITCH bandwidth amplification in mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.017+00:00","url":"https://junglewise.ai/threats/cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto"},{"cve":"CVE-2026-49475","cvss":7.5,"slug":"cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser","title":"SignalWire FreeSWITCH out-of-bounds memory access in STUN parser","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:47.39+00:00","url":"https://junglewise.ai/threats/cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser"},{"cve":"CVE-2026-45771","cvss":7.5,"slug":"cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish","title":"FreeSWITCH XML entity expansion denial of service in SIP PUBLISH","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:33.303+00:00","url":"https://junglewise.ai/threats/cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish"},{"cve":"CVE-2026-49843","cvss":5.3,"slug":"cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session","title":"FreeSWITCH improper authentication in mod_verto allows session eviction","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.17+00:00","url":"https://junglewise.ai/threats/cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session"},{"cve":"CVE-2026-49472","cvss":5.3,"slug":"cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone","title":"FreeSWITCH denial of service in XML-RPC via libexpat clone","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:47.243+00:00","url":"https://junglewise.ai/threats/cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone"},{"cve":"CVE-2026-49848","cvss":4.3,"slug":"cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth","title":"FreeSWITCH mod_verto userVariables injection in check_auth","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.46+00:00","url":"https://junglewise.ai/threats/cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}