WebSocket Stack Overflow in FreeSWITCH by SignalWire
CVE-2026-49847
7.5HIGH
What is CVE-2026-49847?
FreeSWITCH, a Software Defined Telecom Stack, is susceptible to a stack overflow due to a malformed unauthenticated WebSocket frame containing a deeply nested JSON document. This flaw can lead to a crash of the FreeSWITCH process, severing all active calls and sessions. The recursion can disrupt the worker thread's stack execution, ultimately causing the process to terminate. Users are advised to update to version 1.11.1, where the issue has been resolved, to ensure uninterrupted service and mitigate potential exploitation.
Affected Version(s)
freeswitch < 1.11.1
