Vulnerability Description
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts to causes the parser to read and write past the end of the attribute, producing an out-of-bounds memory access on the per-leg media buffer. This issue has been patched in version 1.11.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freeswitch | Freeswitch | < 1.11.0 |
Related Weaknesses (CWE)
References
- https://github.com/signalwire/freeswitch/releases/tag/v1.11.0Release Notes
- https://github.com/signalwire/freeswitch/security/advisories/GHSA-9j6h-hc95-q926Third Party Advisory
FAQ
What is CVE-2026-49475?
CVE-2026-49475 is a vulnerability with a CVSS score of 7.5 (HIGH). FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version ...
How severe is CVE-2026-49475?
CVE-2026-49475 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49475?
Check the references section above for vendor advisories and patch information. Affected products include: Freeswitch Freeswitch.