Vulnerability in FreeSWITCH's XML Parser Allows Network Attackers to Exploit Resources
CVE-2026-45771
7.5HIGH
What is CVE-2026-45771?
FreeSWITCH, a Software Defined Telecom Stack, is affected by a parsing issue in its XML component before the release of version 1.11.0. The bundled XML parser does not impose limits on the expansion of nested declarations. This flaw allows attackers to craft a small Document Type Definition (DTD) that expands excessively, potentially leading to resource exhaustion through unbounded CPU and memory consumption during processing of SIP PUBLISH messages. An unauthenticated network attacker can exploit this scenario by sending a specially crafted request, impacting system performance and availability. The issue is addressed in FreeSWITCH version 1.11.0.
Affected Version(s)
freeswitch < 1.11.0
