Description
libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the parsing of HTTP/2 HPACK path header. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-31036.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the HTTP/2 HPACK path header parsing of libwebsockets. A crafted path header can cause an out‑of‑bounds write because the parser does not validate user‑supplied data. This buffer overflow can overwrite adjacent memory and allow an attacker to execute code in the context of the running process, giving full control of the affected application.

Affected Systems

All implementations of libwebsockets that enable HTTP/2 HPACK path header parsing are affected, as the flaw exists in every version up to the one that includes commit 824151862f37bc72f46d9a3e01d5b9408d313a0b. The affected vendor is libwebsockets: libwebsockets; any deployment using this library without the referenced patch remains vulnerable.

Risk and Exploitability

The CVSS score of 9.8 reflects that this remote code execution flaw is critical. Its EPSS score is reported as less than 1%, indicating a very low current exploitation probability, and it is not yet listed in the CISA KEV catalog. However, the lack of authentication and the ability to trigger the overflow via crafted HTTP/2 traffic mean that an attacker who can reach the vulnerable service can easily exploit the flaw. The likely attack vector is remote network traffic—anyone with network access to the libwebsockets service can send malicious HTTP/2 requests and trigger the vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 14:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libwebsockets to the latest stable release that incorporates the patch in commit 824151862f37bc72f46d9a3e01d5b9408d313a0b.
  • If an upgrade cannot be performed immediately, disable HTTP/2 support or restrict unauthenticated access to any services that use libwebsockets to prevent malicious headers from reaching the parser.
  • Deploy network controls, such as firewall rules or application‑layer filters, that detect and block abnormal HPACK path headers and monitor logs for suspicious activity to reduce the exposure until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6529-1 libwebsockets security update
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Libwebsockets
Libwebsockets libwebsockets
Vendors & Products Libwebsockets
Libwebsockets libwebsockets

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of HTTP/2 HPACK path header. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-31036.
Title libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Weaknesses CWE-787
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Libwebsockets Libwebsockets
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-09-16T03:57:34.021Z

Reserved: 2026-08-13T17:33:16.820Z

Link: CVE-2026-19773

cve-icon Vulnrichment

Updated: 2026-09-15T19:20:36.563Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:17.747

Modified: 2026-09-18T19:10:46.443

Link: CVE-2026-19773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses