PT-2026-45865 · Warmcat · Libwebsockets

·

CVE-2026-10650

·

Published

2026-06-02

·

Updated

2026-06-12

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions warmcat libwebsockets versions prior to 4.5.9
Description A flaw in the SSH Protocol Handler component allows for remote resource consumption. The issue exists within the lws ssh parse plaintext() function located in the plugins/protocol lws ssh base/sshd.c file. An attacker can trigger this by manipulating the msg len argument.
Recommendations Apply patch 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498 to remediate the issue.

Exploit

Fix

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10650
OESA-2026-2668

Affected Products

Libwebsockets