Source record · tier 2 current vendor documentation
Pre-authentication heap buffer overflow in mod_verto HTTP POST body read
- Publisher
- SignalWire
- URL
- https://github.com/signalwire/freeswitch/security/advisories/GHSA-wfrq-qvg2-f88f
- Published
- 2026-06-03
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- GitHub-hosted advisory authored by SignalWire; no-redistribution; short excerpts and locators only
Source notes citing this source
- CVE-2026-49841 (GHSA-wfrq-qvg2-f88f, CVSS 9.8) is a heap buffer overflow in mod_verto's HTTP POST body handling that can be triggered before authentication; it affects FreeSWITCH 1.11.0 and earlier and is fixed in 1.11.1. in context
Cite this source record
APA
WarmTransfer. (2026, June 3). Pre-authentication heap buffer overflow in mod_verto HTTP POST body read. WarmTransfer. https://warmtransfer.net/knowledge/sources/gh-signalwire-freeswitch-ghsa-wfrq-qvg2-f88f
BibTeX
@misc{warmtransfer-gh-signalwire-freeswitch-ghsa-wfrq-qvg2-f88f,
title = {Pre-authentication heap buffer overflow in mod_verto HTTP POST body read},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/gh-signalwire-freeswitch-ghsa-wfrq-qvg2-f88f},
note = {SignalWire, accessed 2026-09-24}
}