chiprook
← Security
SecurityOctober 7, 2026, 19:40

FreeSWITCH mod_verto heap overflow rated CVSS 9.8

In FreeSWITCH before 1.11.1, the mod_verto module allocates a fixed 2 MiB buffer for a POST body but accepts a Content-Length of just under 10 MiB, allowing a heap overflow. The flaw, CVE-2026-49841, has a CVSS score of 9.8 and is fixed in 1.11.1.

FreeSWITCH mod_verto heap overflow rated CVSS 9.8
#FreeSWITCH
Read next
Security

Five of Nine FreeSWITCH CVEs Live in the mod_verto Module

Security

Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed

Security

CTranslate2 CVE-2026-102566 & CVE-2026-102567: Heap Overflow in AI Model Loader

Security

Apache fixes CVE-2026-63292 in httpd 2.4.69: stack overflow in mod_vhost_alias