CVE-2026-49840
FreeSWITCH before version 1.11.1 can be tricked into allocating a negative size when parsing a Content-Length header, which can corrupt the heap or crash the process. An attacker can send a crafted ESL frame with a negative Content-Length before authentication, potentially causing denial of service or arbitrary code execution.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
FreeSWITCH software, versions prior to 1.11.1, used by telecom operators and service providers running on commodity hardware.
Real-world impact
An attacker could crash the FreeSWITCH process or corrupt memory, leading to denial of service or potentially arbitrary code execution.
Why this severity
The CVSS score reflects that the flaw can be exploited remotely without authentication, and it can destroy or crash the system, affecting integrity and availability.
What to do about it
- 01Upgrade FreeSWITCH to version 1.11.1 or later.
- 02Restart the FreeSWITCH service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 23, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/signalwire/freeswitch/relea…release notes
- github.com/signalwire/freeswitch/secur…third party advisory