Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the library to its latest stable release, if not possible backport the fix commit 2f082ec31261f556969160143ba94875d783971a
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4373-1 | libwebsockets security update |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Warmcat
Warmcat libwebsockets |
|
| Vendors & Products |
Warmcat
Warmcat libwebsockets |
Tue, 21 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 20 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service. | |
| Title | Use After Free in libwebsockets WebSocket server | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2025-10-24T10:54:30.961Z
Reserved: 2025-10-13T09:56:10.952Z
Link: CVE-2025-11677
Updated: 2025-10-20T13:54:12.114Z
Status : Deferred
Published: 2025-10-20T14:15:39.357
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11677
OpenCVE Enrichment
Updated: 2025-10-21T09:39:46Z
Debian DLA