Source: libwebsockets X-Debbugs-CC: [email protected] Severity: grave Tags: security
Hi, The following vulnerability was published for libwebsockets. CVE-2026-19773[0]: | libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write | Remote Code Execution Vulnerability. This vulnerability allows | remote attackers to execute arbitrary code on affected installations | of libwebsockets. Authentication is not required to exploit this | vulnerability. The specific flaw exists within the parsing of | HTTP/2 HPACK path header. The issue results from the lack of proper | validation of user-supplied data, which can result in a write past | the end of an allocated buffer. An attacker can leverage this | vulnerability to execute code in the context of the current process. | Was ZDI-CAN-31036. https://www.zerodayinitiative.com/advisories/ZDI-26-590/ Fixed by: https://github.com/warmcat/libwebsockets/commit/824151862f37bc72f46d9a3e01d5b9408d313a0b (v5.0.0) If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-19773 https://www.cve.org/CVERecord?id=CVE-2026-19773 Please adjust the affected versions in the BTS as needed.

