Source record · tier 2 current vendor documentation
Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
- Publisher
- SignalWire
- URL
- https://github.com/signalwire/freeswitch/security/advisories/GHSA-5vjg-pv56-vg4c
- Published
- 2026-05-14
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- GitHub-hosted advisory authored by SignalWire; no-redistribution; short excerpts and locators only
Source notes citing this source
- CVE-2026-45771 (GHSA-5vjg-pv56-vg4c, CVSS 7.5) lets a SIP PUBLISH with nested XML entities exhaust CPU and memory through mod_sofia's presence handling; it affects 1.10.12 and earlier and is fixed in 1.11.0. in context
- Until they can upgrade, the advisory for CVE-2026-45771 suggests limiting affected SIP listeners to trusted networks, or setting manage-presence=false on untrusted profiles, which also disables presence features such as BLF. in context
Cite this source record
APA
WarmTransfer. (2026, May 14). Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion. WarmTransfer. https://warmtransfer.net/knowledge/sources/gh-signalwire-freeswitch-ghsa-5vjg-pv56-vg4c
BibTeX
@misc{warmtransfer-gh-signalwire-freeswitch-ghsa-5vjg-pv56-vg4c,
title = {Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/gh-signalwire-freeswitch-ghsa-5vjg-pv56-vg4c},
note = {SignalWire, accessed 2026-09-24}
}