Skip to content

Build1 publisher3 min readPublished

Turning off mod_verto retires five of FreeSWITCH's nine June CVEs

Five of nine FreeSWITCH CVEs from June 2026 sit in mod_verto, including an unauthenticated 9.8 heap overflow that unloading the module closes without a patch. The second critical, a 9.1 in the Event Socket Library, stays loaded and reaches any binary linked against libesl.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The Event Socket Library flaw is reachable to a man-in-the-middle on an ESL connection unless that socket is bound to loopback.
  • CVE-2026-49475 is a STUN out-of-bounds read on the media buffer that WebRTC traffic reaches whether or not an install runs Verto at all.
  • The advisories list fixes across two releases: three issues in 1.11.0 and the other six in 1.11.1, so landing on 1.11.0 alone leaves both criticals open.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • capability An operator who runs no browser clients can retire five of the nine CVEs, including the 9.8, by unloading one module from fs_cli, with no maintenance window and no regression to the call path.
  • constraint The unload touches none of the four non-Verto CVEs, so the 9.1 Event Socket Library critical still needs a patched build on every box.
  • exposure The libesl bug reaches binaries most teams never patch for telephony, including event dashboards, billing hooks and monitoring scripts linked against the library.
  • decision Installs on the 1.10 stable line cannot confirm coverage from the advisories, so the fix burden becomes asking the packager whether each CVE ID is addressed.

Unloading mod_verto removes the five CVEs that live there, including the 9.8 [3][16]. The second critical, a 9.1 in the Event Socket Library, is a different module and stays loaded [9]. After the unload, four CVEs remain, and one of them is still rated critical [1].

The author of the analysis pulled all nine CVEs from the NVD API rather than a vendor bulletin, on the grounds that scores and vectors get copied around with errors [2]. Grouped that way, the 9.8 is a textbook fixed-buffer overflow. CVE-2026-49841 allocates a 2 MiB buffer for a urlencoded POST body, then accepts a Content-Length just under 10 MiB, and the read loop trusts the header value instead of the buffer size [4]. That is room for nearly 8 MiB of writes past a 2 MiB allocation [2]. It is unauthenticated, network reachable, and needs no user interaction [5].

The cluster in mod_verto is mostly an auth-ordering story. CVE-2026-49842 parses a hash-prefixed speed-test protocol before any authentication check, reading the payload size with atoi and rejecting only non-positive values [6]. The two lower-scored bugs, 49843 and 49848, write state from a client request before the credential check runs [8]. CVE-2026-49847 does not need the pattern: one unauthenticated WebSocket frame of deeply nested JSON pushes the worker's stack down into its guard page, and the crash ends every call the host is carrying [7].

Unloading works for so many installs because of the default config. mod_verto ships in the default modules.conf.xml, and plenty of boxes carry it only because nobody pruned it; `show modules` in fs_cli shows whether yours does [15]. The author's own images make the point. The module list staged for the ICTCore and ICTFax builds has 53 modules, mod_event_socket present and mod_verto absent, because a fax and voice server has no reason to serve browser clients [17].

ESL is the flaw that applies to almost everyone. CVE-2026-49840 parses Content-Length with atol and hands it to malloc with no sign or magnitude check, so a negative length corrupts the heap [9]. It affects any process linked against libesl, not just FreeSWITCH [10]. A monitoring script, an event dashboard, or a billing hook linked against it is in scope, and none of those usually sits on a telephony patch list [10]. A man-in-the-middle on an ESL connection is a realistic position unless the socket is bound to loopback [11].

Three more sit outside both modules. CVE-2026-49475 reads a STUN attribute whose declared length is shorter than the struct the parser casts it to, an out-of-bounds access on the per-leg media buffer that WebRTC traffic reaches whether or not Verto runs [14]. The other two are bundled XML: a billion-laughs expansion through the PIDF body of a SIP PUBLISH, reached before any digest check [12], and an expat clone inside the bundled xmlrpc-c that never got an upstream security patch [13].

Then the version problem. The advisories name the fixed releases as 1.11.0 and 1.11.1, with three issues fixed in 1.11.0 and the other six in 1.11.1, so stopping at 1.11.0 leaves both criticals open [18]. 1.11 is FreeSWITCH's master branch. Most installs in production sit on 1.10 stable, and nothing in the advisories says whether any later 1.10 release picked up the fixes [19]. The author's own Docker image pulls 1.10.12 and an older Ubuntu script still pins 1.10.11 [20].

On whether stable is safe, the analysis declines to guess. "I am not going to tell you that 1.10.x is safe, and I am not going to tell you it is exploitable," the author wrote [21]. The practical step is to ask the packager of your build if the version you run covers these exact CVE IDs, and to treat a shrug as a no [22].

What to watch

  • Whether FreeSWITCH backports these specific fixes into a 1.10 stable release, which would give most production installs a patch path instead of a module unload.
  • Whether packagers such as the Copr repo and the Ubuntu install scripts move off pinned 1.10.11 and 1.10.12 builds.
  • Whether CVE-2026-49475 gets a separate fix, since the STUN media-buffer path is reachable through WebRTC with Verto unloaded.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories