Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libwebsockets | Nov 19, 2025 | Nov 19, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libwebsockets | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libwebsockets | Jan 15, 2026 | Dec 11, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade libwebsockets | Dec 12, 2025 | Dec 11, 2025 |
| Ubuntu | — | Upgrade libwebsockets15 (Ubuntu Pro)Upgrade libwebsockets16Upgrade libwebsockets19t64 (Ubuntu Pro) | Feb 13, 2026 | Feb 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub