CVE-2025-11679
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-20
Last updated on: 2025-10-21
Assigner: Nozomi Networks Inc.
Description
Description
Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| warmcat | libwebsockets | 4.4.2 |
| warmcat | libwebsockets | 4.1 |
| warmcat | libwebsockets | 4.3.6 |
| warmcat | libwebsockets | 4.2 |
| warmcat | libwebsockets | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |