Five of Nine FreeSWITCH CVEs Live in the mod_verto Module
Nine FreeSWITCH CVEs were published in June 2026, two rated critical at 9.8 and 9.1. Five sit in mod_verto and its WebSocket handling, including the heap overflow CVE-2026-49841. Fixes land in 1.11.0 and 1.11.1, but it is unclear whether they were backported to the 1.10 stable line.
- CVE-2026-49841 (9.8) is a heap overflow in the mod_verto HTTP request handler
- CVE-2026-49840 (9.1) corrupts the heap in the Event Socket Library (libesl)
- Five flaws are in mod_verto, two in bundled XML parsing, one in STUN handling
- Three CVEs are fixed in 1.11.0, the other six in 1.11.1
Read next
Security