USN-8893-1: Libwebsockets vulnerabilities
It was discovered that libwebsockets did not properly validate
user-supplied data when parsing HTTP/2 HPACK path headers, which could
result in a write past the end of an allocated buffer. An attacker could
possibly use this issue to execute arbitrary code. (CVE-2026-19773)
It was discovered that libwebsockets did not properly handle CBOR
recording in the LECP parser, which could result in a write past the end
of an allocated buffer. An attacker could possibly use this issue to
cause a crash or execute arbitrary code. (CVE-2026-78161)