Impact
The vulnerability resides in the HTTP/2 HPACK path header parsing of libwebsockets. A crafted path header can cause an out‑of‑bounds write because the parser does not validate user‑supplied data. This buffer overflow can overwrite adjacent memory and allow an attacker to execute code in the context of the running process, giving full control of the affected application.
Affected Systems
All implementations of libwebsockets that enable HTTP/2 HPACK path header parsing are affected, as the flaw exists in every version up to the one that includes commit 824151862f37bc72f46d9a3e01d5b9408d313a0b. The affected vendor is libwebsockets: libwebsockets; any deployment using this library without the referenced patch remains vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects that this remote code execution flaw is critical. Its EPSS score is reported as less than 1%, indicating a very low current exploitation probability, and it is not yet listed in the CISA KEV catalog. However, the lack of authentication and the ability to trigger the overflow via crafted HTTP/2 traffic mean that an attacker who can reach the vulnerable service can easily exploit the flaw. The likely attack vector is remote network traffic—anyone with network access to the libwebsockets service can send malicious HTTP/2 requests and trigger the vulnerability.
OpenCVE Enrichment
Debian DSA