๐Ÿ” CVE Alert

CVE-2026-78161

HIGH 7.3

warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.

CWE CWE-787 CWE-119
Vendor warmcat
Product libwebsockets
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for warmcat libwebsockets

Be the first to know when new high vulnerabilities affecting warmcat libwebsockets are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

warmcat / libwebsockets
4.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/394543 vuldb.com: https://vuldb.com/vuln/394543/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78161 vuldb.com: https://vuldb.com/submit/883225 github.com: https://github.com/biniamf/pocs/tree/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write github.com: https://github.com/biniamf/pocs/blob/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write/poc_lecp_cbor_pos_oob.c github.com: https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054 github.com: https://github.com/warmcat/libwebsockets/

Credits

๐Ÿ” biniam (VulDB User)