Source note · FreeSWITCH
CVE-2026-45771 (GHSA-5vjg-pv56-vg4c, CVSS 7.5) lets a SIP PUBLISH with nested XML entities exhaust CPU and memory through mod_sofia's presence handling; it affects 1.10.12 and earlier and is fixed in 1.11.0.
Checked 2026-09-24
- Vendor
- SignalWire
- Product
- FreeSWITCH
- Subsystem
- security
- Deployment
- on-premises, cloud
- Region
- not restricted
- Release range
- <= 1.10.12 affected; 1.11.0 fixed
- Checked
- 2026-09-24
Sources
- Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion — SignalWire · tier 2 current vendor documentation · Advisory header and key details
Cite this note
APA
WarmTransfer. (2026, September 24). FreeSWITCH: source note freeswitch-pbx-cve-2026-45771-publish-xee. WarmTransfer. https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-45771-publish-xee
BibTeX
@misc{warmtransfer-claim-freeswitch-pbx-cve-2026-45771-publish-xee,
title = {FreeSWITCH: source note freeswitch-pbx-cve-2026-45771-publish-xee},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-45771-publish-xee},
note = {Source note freeswitch-pbx-cve-2026-45771-publish-xee, checked 2026-09-24}
}