Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10650

Опубликовано: 02 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

A flaw was found in libwebsockets, specifically within its SSH Protocol Handler component. A remote attacker can exploit this vulnerability by manipulating the 'msg_len' argument in the 'lws_ssh_parse_plaintext' function. This manipulation can lead to excessive resource consumption, resulting in a Denial of Service (DoS) condition for the affected system.

Меры по смягчению последствий

To mitigate this issue, restrict network access to systems running the libwebsockets SSH Protocol Handler to trusted clients only. If the SSH Protocol Handler functionality is not required, consider disabling or removing components that utilize it to reduce exposure. Consult product documentation for specific instructions on disabling or configuring the libwebsockets SSH Protocol Handler within your Red Hat product.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1libwebsocketsFix deferred
Red Hat OpenStack Platform 16.2libwebsocketsFix deferred
Red Hat OpenStack Platform 17.1libwebsocketsFix deferred
Red Hat Service Interconnect 1libwebsocketsFix deferred
Red Hat Service Interconnect 2libwebsocketsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2484180libwebsockets: libwebsockets: Denial of Service via SSH Protocol Handler resource consumption

EPSS

Процентиль: 35%
0.00429
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

CVSS3: 5.3
nvd
около 2 месяцев назад

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

CVSS3: 5.3
debian
около 2 месяцев назад

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue ...

CVSS3: 5.3
github
около 2 месяцев назад

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

EPSS

Процентиль: 35%
0.00429
Низкий

5.3 Medium

CVSS3