Libwebsockets (LWS) is a flexible, lightweight pure C library for implementing modern network protocols easily with a tiny footprint, using a nonblocking event loop.
Security Fix(es):
Use After Free vulnerability exists in the WebSocket server implementation in lwshandshakeserver in warmcat libwebsockets. In specific configurations where the user provides a callback function that handles LWSCALLBACKHTTPCONFIRMUPGRADE, an attacker may achieve denial of service.(CVE-2025-11677)
Stack-based Buffer Overflow in lwsadnsparselabel in warmcat libwebsockets allows, when the LWSWITHSYSASYNCDNS flag is enabled during compilation, to overflow the labelstack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.(CVE-2025-11678)
{
    "severity": "High"
}{
    "x86_64": [
        "libwebsockets-4.3.0-7.oe2003sp4.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.0-7.oe2003sp4.x86_64.rpm",
        "libwebsockets-debugsource-4.3.0-7.oe2003sp4.x86_64.rpm",
        "libwebsockets-devel-4.3.0-7.oe2003sp4.x86_64.rpm"
    ],
    "aarch64": [
        "libwebsockets-4.3.0-7.oe2003sp4.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.0-7.oe2003sp4.aarch64.rpm",
        "libwebsockets-debugsource-4.3.0-7.oe2003sp4.aarch64.rpm",
        "libwebsockets-devel-4.3.0-7.oe2003sp4.aarch64.rpm"
    ],
    "noarch": [
        "libwebsockets-help-4.3.0-7.oe2003sp4.noarch.rpm"
    ],
    "src": [
        "libwebsockets-4.3.0-7.oe2003sp4.src.rpm"
    ]
}{
    "x86_64": [
        "libwebsockets-4.3.0-7.oe2203sp3.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.0-7.oe2203sp3.x86_64.rpm",
        "libwebsockets-debugsource-4.3.0-7.oe2203sp3.x86_64.rpm",
        "libwebsockets-devel-4.3.0-7.oe2203sp3.x86_64.rpm"
    ],
    "aarch64": [
        "libwebsockets-4.3.0-7.oe2203sp3.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.0-7.oe2203sp3.aarch64.rpm",
        "libwebsockets-debugsource-4.3.0-7.oe2203sp3.aarch64.rpm",
        "libwebsockets-devel-4.3.0-7.oe2203sp3.aarch64.rpm"
    ],
    "noarch": [
        "libwebsockets-help-4.3.0-7.oe2203sp3.noarch.rpm"
    ],
    "src": [
        "libwebsockets-4.3.0-7.oe2203sp3.src.rpm"
    ]
}{
    "x86_64": [
        "libwebsockets-4.3.0-7.oe2203sp4.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.0-7.oe2203sp4.x86_64.rpm",
        "libwebsockets-debugsource-4.3.0-7.oe2203sp4.x86_64.rpm",
        "libwebsockets-devel-4.3.0-7.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "libwebsockets-4.3.0-7.oe2203sp4.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.0-7.oe2203sp4.aarch64.rpm",
        "libwebsockets-debugsource-4.3.0-7.oe2203sp4.aarch64.rpm",
        "libwebsockets-devel-4.3.0-7.oe2203sp4.aarch64.rpm"
    ],
    "noarch": [
        "libwebsockets-help-4.3.0-7.oe2203sp4.noarch.rpm"
    ],
    "src": [
        "libwebsockets-4.3.0-7.oe2203sp4.src.rpm"
    ]
}{
    "x86_64": [
        "libwebsockets-4.3.3-4.oe2403.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403.x86_64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403.x86_64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403.x86_64.rpm",
        "libwebsockets-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-4.3.3-4.oe2403sp2.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp2.x86_64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp2.x86_64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp2.x86_64.rpm"
    ],
    "aarch64": [
        "libwebsockets-4.3.3-4.oe2403.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403.aarch64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403.aarch64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403.aarch64.rpm",
        "libwebsockets-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-4.3.3-4.oe2403sp2.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp2.aarch64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp2.aarch64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp2.aarch64.rpm"
    ],
    "noarch": [
        "libwebsockets-help-4.3.3-4.oe2403.noarch.rpm",
        "libwebsockets-help-4.3.3-4.oe2403sp1.noarch.rpm",
        "libwebsockets-help-4.3.3-4.oe2403sp2.noarch.rpm"
    ],
    "src": [
        "libwebsockets-4.3.3-4.oe2403.src.rpm",
        "libwebsockets-4.3.3-4.oe2403sp1.src.rpm",
        "libwebsockets-4.3.3-4.oe2403sp2.src.rpm"
    ]
}{
    "x86_64": [
        "libwebsockets-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp1.x86_64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "libwebsockets-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp1.aarch64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp1.aarch64.rpm"
    ],
    "noarch": [
        "libwebsockets-help-4.3.3-4.oe2403sp1.noarch.rpm"
    ],
    "src": [
        "libwebsockets-4.3.3-4.oe2403sp1.src.rpm"
    ]
}{
    "x86_64": [
        "libwebsockets-4.3.3-4.oe2403sp2.x86_64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp2.x86_64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp2.x86_64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp2.x86_64.rpm"
    ],
    "aarch64": [
        "libwebsockets-4.3.3-4.oe2403sp2.aarch64.rpm",
        "libwebsockets-debuginfo-4.3.3-4.oe2403sp2.aarch64.rpm",
        "libwebsockets-debugsource-4.3.3-4.oe2403sp2.aarch64.rpm",
        "libwebsockets-devel-4.3.3-4.oe2403sp2.aarch64.rpm"
    ],
    "noarch": [
        "libwebsockets-help-4.3.3-4.oe2403sp2.noarch.rpm"
    ],
    "src": [
        "libwebsockets-4.3.3-4.oe2403sp2.src.rpm"
    ]
}