Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 11 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-130 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue. | |
| Title | warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption | |
| First Time appeared |
Warmcat
Warmcat libwebsockets |
|
| Weaknesses | CWE-400 CWE-404 |
|
| CPEs | cpe:2.3:a:warmcat:libwebsockets:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Warmcat
Warmcat libwebsockets |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-03T14:04:31.919Z
Reserved: 2026-06-02T15:19:20.070Z
Link: CVE-2026-10650
Updated: 2026-06-03T14:04:27.427Z
Status : Deferred
Published: 2026-06-02T22:16:16.293
Modified: 2026-06-04T13:53:09.797
Link: CVE-2026-10650
OpenCVE Enrichment
Updated: 2026-06-11T02:15:27Z