{"schema_version":1,"title":"SignalWire vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in SignalWire: 0 in the last 7 days and 1 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-49846, was published on 11 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/signalwire","json_url":"https://junglewise.ai/threats/vendors/signalwire.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/signalwire","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":5,"all_time":10,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":1,"last_365_days":10},"latest":[{"cve":"CVE-2026-49846","cvss":7.5,"epss":0.005,"slug":"cve-2026-49846-signalwire-libks-path-traversal-in-http-uri-parser","title":"signalwire libks path traversal in HTTP URI parser","severity":"high","exploited":false,"published_at":"2026-09-11T22:16:37.537+00:00","url":"https://junglewise.ai/threats/cve-2026-49846-signalwire-libks-path-traversal-in-http-uri-parser"},{"cve":"CVE-2026-49848","cvss":4.3,"slug":"cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth","title":"FreeSWITCH mod_verto userVariables injection in check_auth","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.46+00:00","url":"https://junglewise.ai/threats/cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth"},{"cve":"CVE-2026-49847","cvss":7.5,"slug":"cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto","title":"FreeSWITCH stack overflow in cJSON parser via mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.32+00:00","url":"https://junglewise.ai/threats/cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto"},{"cve":"CVE-2026-49843","cvss":5.3,"slug":"cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session","title":"FreeSWITCH improper authentication in mod_verto allows session eviction","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.17+00:00","url":"https://junglewise.ai/threats/cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session"},{"cve":"CVE-2026-49842","cvss":7.5,"slug":"cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto","title":"SignalWire FreeSWITCH bandwidth amplification in mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.017+00:00","url":"https://junglewise.ai/threats/cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto"},{"cve":"CVE-2026-49841","cvss":9.8,"slug":"cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post","title":"SignalWire FreeSWITCH heap overflow in mod_verto HTTP POST handler","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.87+00:00","url":"https://junglewise.ai/threats/cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post"},{"cve":"CVE-2026-49840","cvss":9.1,"slug":"cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content","title":"SignalWire FreeSWITCH heap buffer overflow in libesl Content-Length parsing","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.703+00:00","url":"https://junglewise.ai/threats/cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content"},{"cve":"CVE-2026-49475","cvss":7.5,"slug":"cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser","title":"SignalWire FreeSWITCH out-of-bounds memory access in STUN parser","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:47.39+00:00","url":"https://junglewise.ai/threats/cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser"},{"cve":"CVE-2026-49472","cvss":5.3,"slug":"cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone","title":"FreeSWITCH denial of service in XML-RPC via libexpat clone","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:47.243+00:00","url":"https://junglewise.ai/threats/cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone"},{"cve":"CVE-2026-45771","cvss":7.5,"slug":"cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish","title":"FreeSWITCH XML entity expansion denial of service in SIP PUBLISH","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:33.303+00:00","url":"https://junglewise.ai/threats/cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish"}],"vendor":{"hub":true,"name":"SignalWire","slug":"signalwire","homepage":"https://signalwire.com/","description":"SignalWire is a technology company that provides cloud-native communications APIs and is the primary maintainer of the FreeSWITCH project.","url":"https://junglewise.ai/threats/vendors/signalwire"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-49841","cvss":9.8,"slug":"cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post","title":"SignalWire FreeSWITCH heap overflow in mod_verto HTTP POST handler","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.87+00:00","url":"https://junglewise.ai/threats/cve-2026-49841-signalwire-freeswitch-heap-overflow-in-mod-verto-http-post"},{"cve":"CVE-2026-49840","cvss":9.1,"slug":"cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content","title":"SignalWire FreeSWITCH heap buffer overflow in libesl Content-Length parsing","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:47.703+00:00","url":"https://junglewise.ai/threats/cve-2026-49840-signalwire-freeswitch-heap-buffer-overflow-in-libesl-content"},{"cve":"CVE-2026-49846","cvss":7.5,"epss":0.005,"slug":"cve-2026-49846-signalwire-libks-path-traversal-in-http-uri-parser","title":"signalwire libks path traversal in HTTP URI parser","severity":"high","exploited":false,"published_at":"2026-09-11T22:16:37.537+00:00","url":"https://junglewise.ai/threats/cve-2026-49846-signalwire-libks-path-traversal-in-http-uri-parser"},{"cve":"CVE-2026-49847","cvss":7.5,"slug":"cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto","title":"FreeSWITCH stack overflow in cJSON parser via mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.32+00:00","url":"https://junglewise.ai/threats/cve-2026-49847-freeswitch-stack-overflow-in-cjson-parser-via-mod-verto"},{"cve":"CVE-2026-49842","cvss":7.5,"slug":"cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto","title":"SignalWire FreeSWITCH bandwidth amplification in mod_verto","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:48.017+00:00","url":"https://junglewise.ai/threats/cve-2026-49842-signalwire-freeswitch-bandwidth-amplification-in-mod-verto"},{"cve":"CVE-2026-49475","cvss":7.5,"slug":"cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser","title":"SignalWire FreeSWITCH out-of-bounds memory access in STUN parser","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:47.39+00:00","url":"https://junglewise.ai/threats/cve-2026-49475-signalwire-freeswitch-out-of-bounds-memory-access-in-stun-parser"},{"cve":"CVE-2026-45771","cvss":7.5,"slug":"cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish","title":"FreeSWITCH XML entity expansion denial of service in SIP PUBLISH","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:33.303+00:00","url":"https://junglewise.ai/threats/cve-2026-45771-freeswitch-xml-entity-expansion-denial-of-service-in-sip-publish"},{"cve":"CVE-2026-49843","cvss":5.3,"slug":"cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session","title":"FreeSWITCH improper authentication in mod_verto allows session eviction","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.17+00:00","url":"https://junglewise.ai/threats/cve-2026-49843-freeswitch-improper-authentication-in-mod-verto-allows-session"},{"cve":"CVE-2026-49472","cvss":5.3,"slug":"cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone","title":"FreeSWITCH denial of service in XML-RPC via libexpat clone","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:47.243+00:00","url":"https://junglewise.ai/threats/cve-2026-49472-freeswitch-denial-of-service-in-xml-rpc-via-libexpat-clone"},{"cve":"CVE-2026-49848","cvss":4.3,"slug":"cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth","title":"FreeSWITCH mod_verto userVariables injection in check_auth","severity":"medium","exploited":false,"published_at":"2026-06-09T17:17:48.46+00:00","url":"https://junglewise.ai/threats/cve-2026-49848-freeswitch-mod-verto-uservariables-injection-in-check-auth"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"SignalWire Freeswitch","slug":"freeswitch","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/freeswitch"}]}