XML Parsing Vulnerability in FreeSWITCH Software Defined Telecom Stack
CVE-2026-49472
5.3MEDIUM
What is CVE-2026-49472?
FreeSWITCH, an advanced Software Defined Telecom Stack, prior to version 1.11.0, contains a significant XML parsing vulnerability within the PREFIX(prologTok)() function. This function, derived from an outdated version of libexpat, lacks crucial security patches. Consequently, systems utilizing versions prior to 1.11.0 remain exposed to potential exploits. Users are strongly urged to upgrade to version 1.11.0, where this vulnerability has been addressed and patched, ensuring a more secure implementation.
Affected Version(s)
freeswitch < 1.11.0
