Source note · FreeSWITCH
CVE-2026-49841 (GHSA-wfrq-qvg2-f88f, CVSS 9.8) is a heap buffer overflow in mod_verto's HTTP POST body handling that can be triggered before authentication; it affects FreeSWITCH 1.11.0 and earlier and is fixed in 1.11.1.
Checked 2026-09-24
- Vendor
- SignalWire
- Product
- FreeSWITCH
- Subsystem
- security
- Deployment
- on-premises, cloud
- Region
- not restricted
- Release range
- <= 1.11.0 affected; >= 1.11.1 fixed
- Checked
- 2026-09-24
Sources
- Pre-authentication heap buffer overflow in mod_verto HTTP POST body read — SignalWire · tier 2 current vendor documentation · Advisory header (affected/patched versions, severity, CVE) and description
Cite this note
APA
WarmTransfer. (2026, September 24). FreeSWITCH: source note freeswitch-pbx-cve-2026-49841-verto. WarmTransfer. https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-49841-verto
BibTeX
@misc{warmtransfer-claim-freeswitch-pbx-cve-2026-49841-verto,
title = {FreeSWITCH: source note freeswitch-pbx-cve-2026-49841-verto},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-49841-verto},
note = {Source note freeswitch-pbx-cve-2026-49841-verto, checked 2026-09-24}
}