CVE-2025-11678: Warmcat Libwebsocket
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.
Affected products
- Warmcat Libwebsocket: from 4.0, up to and including 4.4.2; from 4.0, up to and including 4.3.6
Published 2025-10-20. Last modified 2026-10-08.