Security Advisories

Stay up to date with the latest security advisories for the
Asterisk Project.

Stack buffer overflow in res_xmpp XMPP namespace prefix handling: (GHSA-mxgm-8c6f-5p8f)

June 25, 2026

Asterisk app_sms.c copies externally controlled SMS lengths into fixed in-struct buffers: (GHSA-q9fr-m7g8-6ph5)

June 25, 2026

Stack Buffer Overflow in H.323 ooTrace() via Unbounded vsprintf into Fixed 2048-byte Buffer: (GHSA-x348-j6c9-77f3)

June 25, 2026

NULL Pointer Dereference in HTTP AMI Digest Authentication: (GHSA-3rhj-hhw7-m6fw)

June 25, 2026

Out-of-Bounds Write in Codec2 Decoder Due to Floor/Ceil Sample Count Mismatch: (GHSA-qf8j-jp7h-c5hx)

June 25, 2026

What can we help you find?