Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freeswitch
Freeswitch freeswitch |
|
| CPEs | cpe:2.3:a:freeswitch:freeswitch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freeswitch
Freeswitch freeswitch |
Tue, 09 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signalwire
Signalwire freeswitch |
|
| Vendors & Products |
Signalwire
Signalwire freeswitch |
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #SPB / #SPE) before any authentication check. The declared payload size in #SPU was parsed with atoi() and only rejected non-positive values, so an unauthenticated peer could request up to INT_MAX bytes. The server then wrote roughly size * 10 bytes back during the download phase, on the order of 20 GB per request, yielding strong outbound bandwidth amplification from a short request. This issue has been patched in version 1.11.1. | |
| Title | FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T18:39:33.710Z
Reserved: 2026-06-01T18:50:36.057Z
Link: CVE-2026-49842
Updated: 2026-06-09T18:23:04.850Z
Status : Analyzed
Published: 2026-06-09T17:17:48.017
Modified: 2026-06-10T15:06:33.640
Link: CVE-2026-49842
No data.
OpenCVE Enrichment
Updated: 2026-06-09T17:45:10Z