Uncontrolled Recursion in freeswitch - CVE-2026-49847
Published: June 4, 2026
freeswitch
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the bundled cJSON parser in mod_verto when parsing deeply nested JSON in a WebSocket frame before authentication. A remote attacker can send a specially crafted WebSocket frame to cause a denial of service.
Any peer that can reach the WebSocket listener can trigger the issue without authentication or user interaction.