Resource exhaustion in freeswitch - CVE-2026-49842
Published: June 4, 2026
freeswitch
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the mod_verto WebSocket frame loop when processing #SPU / #SPB / #SPE speed-test frames before authentication. A remote attacker can send a specially crafted WebSocket request with a large declared payload size to cause a denial of service.
The issue is reachable before the JSON-RPC dispatcher and authentication gate, and no user interaction is required.