Back to overview

CVE-2025-1866

CRITICAL
10.0
CVSS 4.0
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading to out-of-bounds memory access. This issue affects libwebsockets before 4.3.4 and is present in code built specifically for the Win32 platform. By default, the affected code is not executed unless one of the following conditions is met: LWS_WITHOUT_EXTENSIONS (default ON) is manually set to OFF in CMake. LWS_WITH_HTTP_STREAM_COMPRESSION (default OFF) is manually set to ON in CMake. Despite these conditions, when triggered in affected configurations, this vulnerability may allow attackers to manipulate pointers, potentially leading to memory corruption or unexpected behavior.

Metadata

CVE ID
CVE-2025-1866
State
PUBLISHED
Assigner
GovTech CSG
Reserved
2025-03-03 08:26 UTC
Published
2025-03-03 08:44 UTC
Last updated
2025-03-03 16:34 UTC
Primary CWE
CWE-119
CWE-119 Improper Restriction of Operations within the Bounds…
Vendor / Product
warmcat / libwebsockets
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
warmcat libwebsockets 0 < <4.3.4
Weakness (CWE)
CWESourceDescription
CWE-119 cna CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview