← Terug naar overzicht

A critical out-of-bounds write vulnerability was discovered in warmcat libwebsockets version 4.5.0. The flaw exists in the function report_raw_cbor within lib/misc/lecp.c, part of the LECP CBOR Recording component. The vulnerability can be exploited remotely, allowing attackers to perform out-of-bounds memory writes. A public proof-of-concept exploit has been released, increasing the risk of active exploitation. A patch has been identified via commit 1d44554a1bb262db63ff4e240152a9deecd99054 in the official repository. Users are strongly advised to apply the patch immediately. The vulnerability was publicly disclosed and tracked under CVE-2026-78161.

Affected products

  • warmcat libwebsockets 4.5.0

Related CVE's

  • CVE-2026-78161

Categories

  • Network Infrastructure
  • Web Technologies