CVE-2026-23738: Sangoma Asterisk
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are directly interpolated into the HTML of the page using ast_str_append. The endpoint at GET /httpstatus is the potential vulnerable endpoint relating to asterisk/main /http.c. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.
Affected products
- Sangoma Asterisk: up to and including 20.18.2; from 21.0.0, up to and including 21.12.1; from 22.0.0, up to and including 22.8.2; from 23.0.0, before 23.2.2 (fixed in 23.2.2)
- Sangoma Certified Asterisk: up to and including 18.9; version 20.7 only
Published 2026-02-06. Last modified 2026-06-17.