CVE-2026-49847

HIGH

FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON

Title source: cna
STIX 2.1

Description

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH process via stack overflow, terminating all calls and sessions on the host. The recursion drives the worker thread's stack pointer into the stack guard page, raising SIGSEGV from the kernel before any usable write primitive develops. This issue has been patched in version 1.11.1.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 32.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (2)
freeswitch/freeswitch < 1.11.1
signalwire/freeswitch < 1.11.1
Published Jun 09, 2026
Tracked Since Jun 09, 2026