- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
As of 09/14/2026, signalwire recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, libks had the most security vulnerabilities in the signalwire ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-49846libks has path traversal in kws HTTP parser via URI segment overflow | Exploitation statusNot confirmed | FixNot confirmed | Affected productlibks | Published09/11/2026 | SeverityHigh |
CVE-2026-49848FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto` | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityMedium |
CVE-2026-49847FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityHigh |
CVE-2026-49843FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto` | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityMedium |
CVE-2026-49842FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityHigh |
CVE-2026-49841FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityCritical |
CVE-2026-49840FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityCritical |
CVE-2026-49475FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityHigh |
CVE-2026-49472FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityMedium |
CVE-2026-45771Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion | Exploitation statusNot known exploited | FixYes | Affected productfreeswitch | Published06/09/2026 | SeverityHigh |
CVE-2023-51443FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation | Exploitation statusPublic exploit | FixNot confirmed | Affected productfreeswitch | Published12/27/2023 | SeverityHigh |
CVE-2023-40019FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names | Exploitation statusPublic exploit | FixNot confirmed | Affected productfreeswitch | Published09/15/2023 | SeverityHigh |
CVE-2023-40018FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID | Exploitation statusPublic exploit | FixNot confirmed | Affected productfreeswitch | Published09/15/2023 | SeverityHigh |
CVE-2023-32307heap-over-flow and integer-overflow in sofia-sip | Exploitation statusPublic exploit | FixNot confirmed | Affected productsofia-sip | Published05/26/2023 | SeverityHigh |
CVE-2023-22741heap-over-flow in stun_parse_attribute in sofia-sip | Exploitation statusPublic exploit | FixNot confirmed | Affected productsofia-sip | Published01/19/2023 | SeverityCritical |
CVE-2022-31002Out-of-bounds Read in Sofia-SIP | Exploitation statusPublic exploit | FixNot confirmed | Affected productsofia-sip | Published05/31/2022 | SeverityHigh |
CVE-2022-31003Heap-based Buffer Overflow and Out-of-bounds Write in Sofia-SIP | Exploitation statusPublic exploit | FixNot confirmed | Affected productsofia-sip | Published05/31/2022 | SeverityCritical |
CVE-2022-31001Out-of-bounds Read in Sofia-SIP | Exploitation statusNot confirmed | FixNot confirmed | Affected productsofia-sip | Published05/31/2022 | SeverityHigh |
CVE-2021-41158FreeSWITCH vulnerable to SIP digest leak for configured gateways | Exploitation statusNot confirmed | FixYes | Affected productfreeswitch | Published10/26/2021 | SeverityMedium |
CVE-2021-41157FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default | Exploitation statusNot confirmed | FixYes | Affected productfreeswitch | Published10/26/2021 | SeverityMedium |
CVE-2021-41105FreeSWITCH susceptible to Denial of Service via invalid SRTP packets | Exploitation statusNot confirmed | FixYes | Affected productfreeswitch | Published10/25/2021 | SeverityHigh |
CVE-2021-41145FreeSWITCH susceptible to Denial of Service via SIP flooding | Exploitation statusNot confirmed | FixYes | Affected productfreeswitch | Published10/25/2021 | SeverityHigh |
CVE-2021-37624FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing | Exploitation statusNot confirmed | FixYes | Affected productfreeswitch | Published10/25/2021 | SeverityHigh |
CVE-2021-36513 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/18/2021 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan