CVE-2026-45771

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser expands nested <!ENTITY> declarations without a depth or count bound, so a small DTD can describe a body that expands exponentially ("billion laughs"). The PIDF body of a SIP PUBLISH is fed to this parser before any digest check, letting an unauthenticated network attacker force unbounded CPU and memory consumption with a single request. This issue has been patched in version 1.11.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freeswitch:freeswitch:*:*:*:*:*:*:*:*

History

20 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) FreeSWITCH es una pila de telecomunicaciones definida por software que permite la transformación digital desde conmutadores de telecomunicaciones propietarios a una implementación de software que se ejecuta en cualquier hardware comercial. Antes de la versión 1.11.0, el analizador XML incluido de FreeSWITCH expande declaraciones <!ENTITY> anidadas sin un límite de profundidad o recuento, por lo que un DTD pequeño puede describir un cuerpo que se expande exponencialmente ('billion laughs'). El cuerpo PIDF de un SIP PUBLISH se alimenta a este analizador antes de cualquier verificación de digest, permitiendo a un atacante de red no autenticado forzar un consumo ilimitado de CPU y memoria con una única solicitud. Este problema ha sido parcheado en la versión 1.11.0.

10 Jun 2026, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:freeswitch:freeswitch:*:*:*:*:*:*:*:*
First Time Freeswitch freeswitch
Freeswitch
References () https://github.com/signalwire/freeswitch/releases/tag/v1.11.0 - () https://github.com/signalwire/freeswitch/releases/tag/v1.11.0 - Product, Release Notes
References () https://github.com/signalwire/freeswitch/security/advisories/GHSA-5vjg-pv56-vg4c - () https://github.com/signalwire/freeswitch/security/advisories/GHSA-5vjg-pv56-vg4c - Mitigation, Vendor Advisory

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-07-20 20:10


NVD link : CVE-2026-45771

Mitre link : CVE-2026-45771

CVE.ORG link : CVE-2026-45771


JSON object : View

Products Affected

freeswitch

  • freeswitch
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')