CVE-2026-49840Freeswitch · Freeswitch
Vulnerability data via NVD (ingested)
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no sign or magnitude check. A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process linked against libesl, before the client has authenticated to that peer. This issue has been patched in version 1.11.1.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-49840product:"Freeswitch Freeswitch"http.html:"Freeswitch"More intel sources (5)
vuln:CVE-2026-49840vulnerabilities.cve_id: CVE-2026-49840CVE-2026-49840CVE-2026-49840"CVE-2026-49840" exploit -site:nvd.nist.gov