Security Advisories

Stay up to date with the latest security advisories for the
Asterisk Project.

Reflected XSS in Phone Provisioning HTTP Error Pages: (GHSA-4pgv-j3mr-3rcp)

June 25, 2026

Buffer over-read in Asterisk PJSIP MWI body parser: (GHSA-8jw3-ccr9-xrmf)

June 25, 2026

Possible RED T.140 Heap Buffer Overflow: (GHSA-vfhr-r9x9-c687)

June 25, 2026

Possible RED T.140 Generation Accumulation OOB Write: (GHSA-j2mm-57pq-jh94)

June 25, 2026

ARI setChannelVar bypasses live_dangerously and permits FILE() writes: (GHSA-vrfp-mg3q-3959)

June 25, 2026

What can we help you find?