CVE-2025-11677

EUVD-2025-35045
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 30.76%
Debian logo
Debian Releases
Debian Product
Codename
libwebsockets
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
4.0.20-2+deb11u1
fixed
forky
4.3.5-5
fixed
sid
4.3.5-5
fixed
trixie
4.3.5-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libwebsockets
bionic
not-affected
focal
Fixed 3.2.1-3ubuntu0.1~esm1
released
jammy
Fixed 4.0.20-2ubuntu1.1
released
noble
Fixed 4.3.3-1.1ubuntu0.1~esm1
released
plucky
ignored
questing
ignored
resolute
not-affected
xenial
not-affected