signalwire Summary
Latest vulnerabilities published by signalwire
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`
CVE-2026-49848SignalwireFreeswitch4.3MEDIUMFreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
CVE-2026-49847SignalwireFreeswitch7.5HIGHFreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`
CVE-2026-49843SignalwireFreeswitch5.3MEDIUMFreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames
CVE-2026-49842SignalwireFreeswitch7.5HIGHFreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
CVE-2026-49841SignalwireFreeswitch9.8CRITICALFreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
CVE-2026-49840SignalwireFreeswitch9.1CRITICALFreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
CVE-2026-49475SignalwireFreeswitch7.5HIGHFreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat
CVE-2026-49472SignalwireFreeswitch5.3MEDIUMFreeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
CVE-2026-45771SignalwireFreeswitch7.5HIGHFreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation
CVE-2023-51443SignalwireFreeswitch7.5HIGHFreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID
CVE-2023-40018signalwirefreeswitch7.5HIGHFreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names
CVE-2023-40019signalwirefreeswitch6.5MEDIUMFreeSWITCH vulnerable to SIP digest leak for configured gateways
CVE-2021-41158SignalwireFreeswitch5.8MEDIUMFreeSWITCH does not authenticate SIP SUBSCRIBE requests by default
CVE-2021-41157SignalwireFreeswitch5.3MEDIUMFreeSWITCH susceptible to Denial of Service via invalid SRTP packets
CVE-2021-41105SignalwireFreeswitch7.5HIGHFreeSWITCH susceptible to Denial of Service via SIP flooding
CVE-2021-41145SignalwireFreeswitch8.6HIGHFreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
CVE-2021-37624SignalwireFreeswitchπΎπ‘7.5HIGHInformation Disclosure Vulnerability in SignalWire FreeSWITCH Software
CVE-2021-36513SignalwireFreeswitch7.5HIGH