WebSocket Vulnerability in FreeSWITCH by SignalWire
CVE-2026-49842

7.5HIGH

Key Information:

Vendor

Signalwire

Vendor
CVE Published:
9 June 2026

What is CVE-2026-49842?

The vulnerability in FreeSWITCH arises from the mod_verto's WebSocket frame loop, which intercepts a speed-test protocol command without executing any authentication checks. This flaw enables an unauthenticated peer to manipulate the server into processing excessively large requests, leading to a significant outbound bandwidth amplification effect. For instances where legitimate peers might be misled, the server could handle requests for data sizes up to approximately 20 GB, resulting in potential for abuse. This security issue was rectified in version 1.11.1.

Affected Version(s)

freeswitch < 1.11.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.