WebSocket Vulnerability in FreeSWITCH by SignalWire
CVE-2026-49842
7.5HIGH
What is CVE-2026-49842?
The vulnerability in FreeSWITCH arises from the mod_verto's WebSocket frame loop, which intercepts a speed-test protocol command without executing any authentication checks. This flaw enables an unauthenticated peer to manipulate the server into processing excessively large requests, leading to a significant outbound bandwidth amplification effect. For instances where legitimate peers might be misled, the server could handle requests for data sizes up to approximately 20 GB, resulting in potential for abuse. This security issue was rectified in version 1.11.1.
Affected Version(s)
freeswitch < 1.11.1
