Source note · FreeSWITCH

CVE-2026-45771 (GHSA-5vjg-pv56-vg4c, CVSS 7.5) lets a SIP PUBLISH with nested XML entities exhaust CPU and memory through mod_sofia's presence handling; it affects 1.10.12 and earlier and is fixed in 1.11.0.

Checked 2026-09-24

Vendor
SignalWire
Product
FreeSWITCH
Subsystem
security
Deployment
on-premises, cloud
Region
not restricted
Release range
<= 1.10.12 affected; 1.11.0 fixed
Checked
2026-09-24

Sources

Cite this note

APA

WarmTransfer. (2026, September 24). FreeSWITCH: source note freeswitch-pbx-cve-2026-45771-publish-xee. WarmTransfer. https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-45771-publish-xee

BibTeX

@misc{warmtransfer-claim-freeswitch-pbx-cve-2026-45771-publish-xee,
  title  = {FreeSWITCH: source note freeswitch-pbx-cve-2026-45771-publish-xee},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-45771-publish-xee},
  note   = {Source note freeswitch-pbx-cve-2026-45771-publish-xee, checked 2026-09-24}
}

Read in context