CVE-2025-11677
20.10.2025, 14:15
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handlesLWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration