Out-of-bounds Read in lws_upng_emit_next_line in warmcat...
Moderate severity
Unreviewed
Published
Oct 20, 2025
to the GitHub Advisory Database
•
Updated Oct 20, 2025
Description
Published by the National Vulnerability Database
Oct 20, 2025
Published to the GitHub Advisory Database
Oct 20, 2025
Last updated
Oct 20, 2025
Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.
References