FreeSWITCH Heap Buffer Overflow Bugs Expose Servers to Pre-Auth Attacks
ID: 0a68f10a-43e3-5bf5-83a3-b2ca60775d3e
STIX ID: report--0a68f10a-43e3-5bf5-83a3-b2ca60775d3e
Feed Name: securityonline.info
Threat Score
FreeSWITCH released fixes for two critical pre-auth heap buffer overflows—CVE-2026-49841 in mod_verto (CVSS 9.8) and CVE-2026-49840 in libesl (CVSS 9.1)—that can crash exposed voice servers and may enable remote code execution; administrators are urged to upgrade to FreeSWITCH v1.11.1 or apply network/workaround mitigations (restrict verto listener, remove vhost entries, disable mod_verto, and isolate ESL control-plane).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
