CVE Database
/

CVE-2025-11678

Back to search

CVE-2025-11678

Published: Oct 20, 2025

Modified: Oct 20, 2025

PUBLISHED

Description

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

VendorProductVersions

warmcat

libwebsocket

affected
4.0 - <= 4.4.2
affected
4.0 - <= 4.3.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now