๐Ÿ” CVE Alert

CVE-2026-50161

UNKNOWN 0.0

libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. The expression 4 + hdr->len can wrap when hdr->len is close to UINT64_MAX, causing the mbuf_get_left() bounds check to pass. The subsequent XOR unmasking loop then writes beyond the heap buffer. Applications using websock_accept() or websock_accept_proto() to implement a WebSocket server are affected, and exploitation can cause attacker-controlled heap corruption or denial of service after the HTTP WebSocket upgrade handshake. This issue is fixed in version 4.8.1.

CWE CWE-190 CWE-787
Vendor baresip
Product re
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for baresip re

Be the first to know when new unknown vulnerabilities affecting baresip re are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

baresip / re
< 4.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h github.com: https://github.com/baresip/re/pull/1584 github.com: https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8 github.com: https://github.com/baresip/re/releases/tag/v4.8.1