CVE-2026-23738

LOW

Asterisk <20.7-cert9, <20.18.2, <21.12.1, <22.8.2, <23.2.2 - Info D...

Title source: llm
STIX 2.1

Description

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are directly interpolated into the HTML of the page using ast_str_append. The endpoint at GET /httpstatus is the potential vulnerable endpoint relating to asterisk/main /http.c. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.

References (1)

Core 1
Core References

Scores

CVSS v3 3.5
EPSS 0.0016
EPSS Percentile 5.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
sangoma/asterisk < 20.18.2
sangoma/certified_asterisk 20.7 cert1 (10 CPE variants)
sangoma/certified_asterisk < 18.9
Published Feb 06, 2026
Tracked Since Feb 18, 2026