CVE-2026-10650: warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lwssshparseplaintext of the file plugins/protocollwssshbase/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msglen can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
warmcat libwebsocketsto a version that resolves this vulnerability.Patch 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10650?
CVE-2026-10650 has a medium severity score of 5.3.
How do I fix CVE-2026-10650?
To fix CVE-2026-10650, upgrade warmcat libwebsockets to version 4.5.9 or later.
What component is affected by CVE-2026-10650?
CVE-2026-10650 affects the SSH Protocol Handler in warmcat libwebsockets.
What type of vulnerability is CVE-2026-10650?
CVE-2026-10650 is a resource consumption vulnerability.
Which function is associated with CVE-2026-10650?
The function lws_ssh_parse_plaintext is associated with CVE-2026-10650.