Vulnerability in FreeSWITCH's XML Parser Allows Network Attackers to Exploit Resources
CVE-2026-45771

7.5HIGH

Key Information:

Vendor

Signalwire

Vendor
CVE Published:
9 June 2026

What is CVE-2026-45771?

FreeSWITCH, a Software Defined Telecom Stack, is affected by a parsing issue in its XML component before the release of version 1.11.0. The bundled XML parser does not impose limits on the expansion of nested declarations. This flaw allows attackers to craft a small Document Type Definition (DTD) that expands excessively, potentially leading to resource exhaustion through unbounded CPU and memory consumption during processing of SIP PUBLISH messages. An unauthenticated network attacker can exploit this scenario by sending a specially crafted request, impacting system performance and availability. The issue is addressed in FreeSWITCH version 1.11.0.

Affected Version(s)

freeswitch < 1.11.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.