Source note · FreeSWITCH

CVE-2026-49841 (GHSA-wfrq-qvg2-f88f, CVSS 9.8) is a heap buffer overflow in mod_verto's HTTP POST body handling that can be triggered before authentication; it affects FreeSWITCH 1.11.0 and earlier and is fixed in 1.11.1.

Checked 2026-09-24

Vendor
SignalWire
Product
FreeSWITCH
Subsystem
security
Deployment
on-premises, cloud
Region
not restricted
Release range
<= 1.11.0 affected; >= 1.11.1 fixed
Checked
2026-09-24

Sources

Cite this note

APA

WarmTransfer. (2026, September 24). FreeSWITCH: source note freeswitch-pbx-cve-2026-49841-verto. WarmTransfer. https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-49841-verto

BibTeX

@misc{warmtransfer-claim-freeswitch-pbx-cve-2026-49841-verto,
  title  = {FreeSWITCH: source note freeswitch-pbx-cve-2026-49841-verto},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/freeswitch-pbx-cve-2026-49841-verto},
  note   = {Source note freeswitch-pbx-cve-2026-49841-verto, checked 2026-09-24}
}

Read in context