Build1 publisherNot yet confirmed elsewhere2 min readPublished
FreeSWITCH mod_verto overflows its 2 MiB buffer when a browser declares a 10 MiB body
FreeSWITCH shipped version 1.11.1 to fix CVE-2026-49841, a CVSS 9.8 heap overflow in mod_verto that an unauthenticated browser request can trigger. The read loop copies up to the client's declared Content-Length into a fixed 2 MiB buffer.
The Engineer · Build desk

What happened
- The overflow happens while FreeSWITCH is still parsing the request, so anyone who can reach the Verto HTTP endpoint can trigger it without a SIP credential.
- Code execution would land in the process that handles call routing, SIP authentication, and the media path, which is the control plane of the phone system.
- A ZoomEye query on October 5 returned 4,066 assets matching the FreeSWITCH service fingerprint and 401 whose web page carried a FreeSWITCH title.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure In many FreeSWITCH deployments the Verto endpoint is published to the whole internet for browser clients, so the unauthenticated attack path is open on those hosts until they run 1.11.1.
- constraint No configuration change removes the overflow, because the copy happens inside the handler itself, so a pre-1.11.1 host stays exploitable until it is upgraded.
- decision A filter has to pass the large bodies that legitimate Verto clients send, so a crude Content-Length rule that blocks the attack also breaks calling.
mod_verto accepts form-encoded POST bodies from browsers running the Verto WebRTC client, and reserves 2 MiB for the body [7][1]. The same handler accepts a Content-Length header of just under 10 MiB [2]. The copy loop is bounded by that declared length, not by the size of the buffer, and nothing in the path compares the two before copying begins [3]. Announce just under 10 MiB and deliver it, and the copy runs past the end of the allocation [8]: roughly 8 MiB beyond a 2 MiB buffer [23].
The shape is familiar in C request handlers. One function decides how much memory to reserve, another decides how much to copy, and nothing forces the two numbers to agree [10]. Here the first number is a compile-time constant and the second is an integer the client supplies in a header [4]. A handler that uses that header as a loop bound is trusting an attacker-supplied integer [11]. According to the dev.to write-up, the safe version rejects a request whose declared length exceeds the buffer, or sizes the allocation from the declared length after applying an upper bound [12].
The 1.11.1 release note is the reference for which build closes which issue [19]. CVE-2026-49841, the 9.8 overflow, is fixed in 1.11.1 [9], while CVE-2026-49472, a function cloned from an outdated libexpat whose upstream patch was never carried across, was fixed one release earlier in 1.11.0 [18]. Only 1.11.1 or later closes both [24]. CVE-2026-49475 and CVE-2026-45771 were published in the same window [19].
If the upgrade has to wait, put the endpoint behind a reverse proxy that terminates TLS and enforces an allowlist of known networks, which removes the anonymous case an attacker will use [15]. Check whether mod_verto is loaded at all, because some installs turn it on for a trial and never turn it off [16]. If it is loaded but unused, it is still listening. Watch the host for crashes too. Exploit attempts are likely to bring the process down whether they fail or succeed, so if the signalling or media process keeps segfaulting, check those crashes against the HTTP access log [17].
The two ZoomEye counts describe different things. The app field comes from protocol behaviour, so it catches installs that never render a product name in a web page; the title field only matches where a management interface or default page exposes an HTML title [21]. Neither is a count of vulnerable systems [22].
What to watch
- Publication of a working exploit for CVE-2026-49841. That would move the risk from exposed scanning to active exploitation.
- Any correction to the 1.11.1 release note on which build closes CVE-2026-49475 and CVE-2026-45771.
- Scanners moving from banner fingerprints to detecting the pre-1.11.1 version. With version detection, the ZoomEye counts would become an actual exposed population.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
In versions before 1.11.1, mod_verto allocates a fixed 2 MiB buffer for a POST body of type application/x-www-form-urlencoded.
- [2]
The module accepts a Content-Length header of just under 10 MiB.
- [3]
The loop that copies the body into the buffer is bounded by the declared Content-Length rather than the buffer size, and nothing in the code path compares the two before the copy begins.
- [4]
The 2 MiB is a compile-time constant and the Content-Length is a runtime header value the client chooses.
- [5]
FreeSWITCH handles call routing, authentication for the SIP layer, and the media path, so code execution in that process reaches the control plane of the phone system.
- [6]
An attacker who can reach the Verto HTTP endpoint over the network does not need a credential to submit the malformed body, because the copy happens while the request is being parsed.
- [7]
FreeSWITCH is a software telecom stack that runs on commodity hardware, and its mod_verto module accepts HTTP POST bodies from browsers that use the Verto WebRTC client.
- [8]
A request that announces a large body and then delivers it can write past the end of the allocation.
- [9]
The flaw is CVE-2026-49841, published with a CVSS base score of 9.8 and fixed in 1.11.1, and the project published a GitHub security advisory.
- [10]
Most heap overflows in C request handlers come from the same shape: one function decides how much memory to reserve, another decides how much to copy, and nothing forces the two numbers to agree.
- [11]
Content-Length is client-controlled, so a handler that uses it as a loop bound is trusting an attacker-supplied integer.
- [12]
The safe pattern is to reject a request whose declared length exceeds the buffer, or to allocate from the declared length after applying an upper bound.
- [13]
The overflow is not something a configuration change can remove, because the copy happens in the handler itself, so patching is the only reliable fix.
- [14]
Input filtering can reduce the attack surface, but a rule inspecting Content-Length must be written carefully, because legitimate Verto clients send large bodies and a filter that rejects them breaks calling.
- [15]
The Verto service is normally published for browser clients and in many deployments is reachable from the whole internet; placing the endpoint behind a reverse proxy that terminates TLS and enforces an allowlist of known networks removes the anonymous case.
- [16]
Some installations enable mod_verto for an experiment and leave it loaded after the trial ends.
- [17]
A failed exploitation attempt and a successful one both tend to fault the process, so repeated segfaults on the media or signalling process deserve a look at the HTTP access log.
- [18]
CVE-2026-49472 covers a function cloned from an outdated version of libexpat where the upstream security patch was never carried across, and it was fixed in 1.11.0.
- [19]
CVE-2026-49475 and CVE-2026-45771 were published at the same time, and the 1.11.1 release note is the single reference for which build closes which issue.
- [20]
A ZoomEye query on 2026-10-05 returned 4,066 assets for app="FreeSWITCH" and 401 for title="FreeSWITCH".
- [21]
The app field matches the service fingerprint ZoomEye derives from protocol behaviour and finds installations that never render a product name in a web page; the title field matches a page's HTML title, which exists only where a management interface or default page exposes one.
- [23]
A declared body of just under 10 MiB copied into a 2 MiB buffer leaves roughly 8 MiB written past the end of the allocation.
- [24]
Because CVE-2026-49472 was fixed in 1.11.0 and CVE-2026-49841 in 1.11.1, only 1.11.1 or later closes both.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toFreeSWITCH mod_verto: a 2 MiB buffer and a 10 MiB Content-Length
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.