PT-2026-47851 · Unknown · Freeswitch
CVE-2026-49847
·
Published
2026-06-09
·
Updated
2026-06-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeSWITCH versions prior to 1.11.1
Description
An unauthenticated WebSocket frame containing a deeply nested JSON document can cause a stack overflow, crashing the process and terminating all active calls and sessions on the host. This occurs because recursion drives the worker thread's stack pointer into the stack guard page, triggering a SIGSEGV (a segmentation fault, which is a specific error caused by accessing memory that the CPU cannot physically address) from the kernel.
Recommendations
Update to version 1.11.1.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freeswitch