CVE-2025-11678
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets
It allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, if the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.
October 8, 2025
This issue affects libwebsockets from (including) 4 and up to (including) 4.3.6, 4.4.2
CVE-2025-11678
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.5
Update the library to its latest stable release, if not possible backport the fix commit 2bb9598562b37c942ba5b04bcde3f7fdf66a9d3a
Raffaele Bova of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

