USN-8893-1: Libwebsockets vulnerabilities

Publication date

7 October 2026

Overview

Libwebsockets could be made to crash or run programs if it received specially crafted network traffic.


Packages

  • libwebsockets - C library for building WebSocket-based network applications

Details

It was discovered that libwebsockets did not properly validate
user-supplied data when parsing HTTP/2 HPACK path headers, which could
result in a write past the end of an allocated buffer. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2026-19773)

It was discovered that libwebsockets did not properly handle CBOR
recording in the LECP parser, which could result in a write past the end
of an allocated buffer. An attacker could possibly use this issue to
cause a crash or execute arbitrary code. (CVE-2026-78161)

It was discovered that libwebsockets did not properly validate
user-supplied data when parsing HTTP/2 HPACK path headers, which could
result in a write past the end of an allocated buffer. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2026-19773)

It was discovered that libwebsockets did not properly handle CBOR
recording in the LECP parser, which could result in a write past the end
of an allocated buffer. An attacker could possibly use this issue to
cause a crash or execute arbitrary code. (CVE-2026-78161)

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libwebsockets19t64 –  4.3.5-3ubuntu1.2+esm1  
24.04 LTS noble libwebsockets19t64 –  4.3.3-1.1ubuntu0.1~esm3  
22.04 LTS jammy libwebsockets16 –  4.0.20-2ubuntu1.1+esm2  
20.04 LTS focal libwebsockets15 –  3.2.1-3ubuntu0.1~esm3  
18.04 LTS bionic libwebsockets8 –  2.0.3-3ubuntu0.1~esm1  
16.04 LTS xenial libwebsockets7 –  1.7.1-1ubuntu0.1~esm1

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›