FreeSWITCH mod_verto heap overflow rated CVSS 9.8
In FreeSWITCH before 1.11.1, the mod_verto module allocates a fixed 2 MiB buffer for a POST body but accepts a Content-Length of just under 10 MiB, allowing a heap overflow. The flaw, CVE-2026-49841, has a CVSS score of 9.8 and is fixed in 1.11.1.
- 2 MiB buffer vs Content-Length up to 10 MiB causes heap overflow
- CVE-2026-49841: CVSS 9.8, fixed in FreeSWITCH 1.11.1
- No credentials needed — copy happens during request parsing
- ZoomEye: 4,066 assets with app="FreeSWITCH" exposed online
Read next
Security