Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78161

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.

A flaw was found in warmcat libwebsockets. A remote attacker could exploit an out-of-bounds write vulnerability in the LECP CBOR Recording component, specifically within the report_raw_cbor function. This could lead to information disclosure, data corruption, or denial of service.

Отчет

A vulnerability was found in libwebsockets 4.5.0 only. This vulnerability in libwebsockets, an out-of-bounds write in the LECP CBOR Recording component, does not affect Red Hat products. The vulnerable code is not present in the versions of libwebsockets shipped with Red Hat offerings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1libwebsocketsNot affected
Red Hat OpenStack Platform 16.2libwebsocketsNot affected
Red Hat OpenStack Platform 17.1libwebsocketsNot affected
Red Hat Satellite 6libwebsocketsNot affected
Red Hat Service Interconnect 2libwebsocketsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2521703libwebsockets: libwebsockets: Out-of-bounds write in LECP CBOR Recording

EPSS

Процентиль: 34%
0.00405
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
25 дней назад

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.

CVSS3: 7.3
nvd
25 дней назад

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.

CVSS3: 7.3
debian
25 дней назад

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is ...

CVSS3: 7.3
github
25 дней назад

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.

EPSS

Процентиль: 34%
0.00405
Низкий

7.3 High

CVSS3