Description
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
Problem types
Product status
3 (semver)
Credits
Raffaele Bova at Nozomi Networks
References
libwebsockets.org/...f082ec31261f556969160143ba94875d783971a
www.nozominetworks.com/...rability-advisories-cve-2025-11677