Security Advisories

Stay up to date with the latest security advisories for the
Asterisk Project.

A specifically malformed Authorization header in an incoming SIP request can cause Asterisk to crash: (GHSA-64qc-9×89-rx5j)

August 28, 2025

Resource exhaustion (DoS) vulnerability: remotely exploitable leak of RTP UDP ports and internal resources: (GHSA-557q-795j-wfx2)

August 28, 2025

Uncontrolled Search-Path Element in safe_asterisk script may allow local privilege escalation : (GHSA-v9q8-9j8m-5xwp)

July 31, 2025

Remote DoS and possible RCE in asterisk/res/res_stir_shaken/verification.c : (GHSA-mrq5-74j5-f5cr)

July 31, 2025

cli_permissions.conf: deny option does not work for disallowing shell commands : (GHSA-c7p6-7mvq-8jq2)

May 22, 2025

What can we help you find?