{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/libwebsockets/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-78161"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libwebsockets"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","cbor"],"_cs_type":"advisory","_cs_vendors":["warmcat"],"content_html":"\u003cp\u003eA memory corruption vulnerability has been identified in the warmcat libwebsockets library, specifically within the LECP (Lightweight Embedded CBOR Parser) component. The flaw exists in the report_raw_cbor function located in lib/misc/lecp.c in version 4.5.0. An attacker can exploit this vulnerability remotely by supplying a specially crafted CBOR payload to an application utilizing the libwebsockets library. This manipulation results in an out-of-bounds write, which may lead to application instability, service disruption, or potentially arbitrary code execution depending on the memory layout and the implementation of the host application. A proof-of-concept exploit has been made public, increasing the risk of exploitation for unpatched systems. Organizations utilizing libwebsockets 4.5.0 should prioritize updating to a patched version or applying the official vendor commit 1d44554a1bb262db63ff4e240152a9deecd99054.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs reconnaissance to identify services or applications utilizing the libwebsockets library version 4.5.0.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious CBOR (Concise Binary Object Representation) payload designed to trigger the out-of-bounds write in the report_raw_cbor function.\u003c/li\u003e\n\u003cli\u003eThe attacker transmits the payload to the target application via the established web socket or network interface.\u003c/li\u003e\n\u003cli\u003eThe libwebsockets library receives the data and passes it to the lecp_parse function for processing within the LECP component.\u003c/li\u003e\n\u003cli\u003eThe function report_raw_cbor performs an insecure write operation due to insufficient bounds checking on the CBOR input.\u003c/li\u003e\n\u003cli\u003eThe out-of-bounds write corrupts adjacent memory regions within the application process space.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the corrupted memory state to achieve a crash or redirect application execution flow.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved, typically resulting in Denial of Service (DoS) or Remote Code Execution (RCE).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-78161 allows a remote, unauthenticated attacker to cause memory corruption in systems using libwebsockets 4.5.0. Given the library's prevalence in embedded devices and networked applications, this poses a high risk to availability and system integrity. While the severity is documented as high (CVSS 7.3), the real-world impact depends on the specific host application's memory protections and the attacker's ability to weaponize the memory corruption for reliable execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the official patch identified by commit 1d44554a1bb262db63ff4e240152a9deecd99054 to all instances of libwebsockets 4.5.0 immediately.\u003c/li\u003e\n\u003cli\u003eIdentify applications within the environment that dynamically link against libwebsockets 4.5.0 and schedule emergency patching.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous CBOR payloads if the environment has known exposure of internal services using this library to the internet.\u003c/li\u003e\n\u003cli\u003eReview development build pipelines to ensure static compilation of libwebsockets does not include the vulnerable 4.5.0 version.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T01:40:32Z","date_published":"2026-08-24T01:40:32Z","id":"https://feed.craftedsignal.io/briefs/2026-08-libwebsockets-oob/","summary":"An out-of-bounds write vulnerability in the libwebsockets LECP CBOR recording function (CVE-2026-78161) allows remote attackers to trigger memory corruption via crafted CBOR data.","title":"Remote Code Execution via Out-of-Bounds Write in libwebsockets LECP Component","url":"https://feed.craftedsignal.io/briefs/2026-08-libwebsockets-oob/"}],"language":"en","title":"CraftedSignal Threat Feed - Libwebsockets","version":"https://jsonfeed.org/version/1.1"}