7.5
CVE-2026-49847
- EPSS 0.41%
- Veröffentlicht 09.06.2026 16:05:08
- Zuletzt bearbeitet 10.06.2026 15:06:45
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH process via stack overflow, terminating all calls and sessions on the host. The recursion drives the worker thread's stack pointer into the stack guard page, raising SIGSEGV from the kernel before any usable write primitive develops. This issue has been patched in version 1.11.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freeswitch ≫ Freeswitch Version < 1.11.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.329 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-674 Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
https://github.com/signalwire/freeswitch/releases/tag/v1.11.1
https://github.com/signalwire/freeswitch/security/advisories/GHSA-2v74-pcgh-75wg