Out-of-Bounds Read Vulnerability in Libwebsockets Affects Multiple Applications
CVE-2025-11679

5.9MEDIUM

Key Information:

Vendor

Warmcat

Vendor
CVE Published:
20 October 2025

What is CVE-2025-11679?

The vulnerability in Libwebsockets arises due to an out-of-bounds read condition in the lws_upng_emit_next_line function. When the LWS_WITH_UPNG flag is enabled and the HTML display stack is utilized, the vulnerability may allow an attacker to read beyond a heap-allocated buffer. This could result in application crashes when users visit maliciously crafted websites containing specially designed PNG files, particularly those with exaggerated height dimensions. Implementing the latest patches is crucial to secure applications against this potential exploit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

libwebsockets 4.0 <= 4.4.2

libwebsockets 4.0 <= 4.3.6

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Raffaele Bova at Nozomi Networks
.