CVE-2026-78161
warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.
| CWE | CWE-787 CWE-119 |
| Vendor | warmcat |
| Product | libwebsockets |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for warmcat libwebsockets
Be the first to know when new high vulnerabilities affecting warmcat libwebsockets are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
warmcat / libwebsockets
4.5.0
References
vuldb.com: https://vuldb.com/vuln/394543 vuldb.com: https://vuldb.com/vuln/394543/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78161 vuldb.com: https://vuldb.com/submit/883225 github.com: https://github.com/biniamf/pocs/tree/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write github.com: https://github.com/biniamf/pocs/blob/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write/poc_lecp_cbor_pos_oob.c github.com: https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054 github.com: https://github.com/warmcat/libwebsockets/
Credits
๐ biniam (VulDB User)