USN-8893-1: two libwebsockets flaws, risk of remote code execution
Ubuntu has published security advisory USN-8893-1: two vulnerabilities in libwebsockets allow crashes or remote code execution.
UptimeMag editorial team · 7 October 2026 · 2 min read

On 7 October 2026, Ubuntu published security advisory USN-8893-1, covering two vulnerabilities in the libwebsockets library, used to build WebSocket-based network applications. For anyone running servers that expose WebSocket or HTTP/2 services, the advisory calls for updating packages as soon as possible: an attacker exploiting these flaws could crash the process or, in the worst case, execute arbitrary code.
The two flaws
The first, CVE-2026-19773, concerns parsing of HTTP/2 HPACK path headers: libwebsockets fails to properly validate user-supplied data, risking a write past the end of an allocated buffer. According to the Ubuntu advisory, this can lead to arbitrary code execution.
The second, CVE-2026-78161, concerns handling of CBOR recording in the LECP parser: here too a write past the allocated buffer can occur, potentially crashing the process or allowing code execution.
Affected packages and fixed versions
The package affected is libwebsockets, in its various forms depending on the release. The fixed versions are:
| Ubuntu release | Package | Fixed version | Note |
|---|---|---|---|
| 26.04 LTS (resolute) | libwebsockets19t64 | 4.3.5-3ubuntu1.2+esm1 | Fix via Ubuntu Pro ESM Apps |
| 24.04 LTS (noble) | libwebsockets19t64 | 4.3.3-1.1ubuntu0.1~esm3 | Fix via Ubuntu Pro ESM Apps |
| 22.04 LTS (jammy) | libwebsockets16 | 4.0.20-2ubuntu1.1+esm2 | Fix via Ubuntu Pro ESM Apps |
| 20.04 LTS (focal) | libwebsockets15 | 3.2.1-3ubuntu0.1~esm3 | Fix via Ubuntu Pro ESM Apps |
| 18.04 LTS (bionic) | libwebsockets8 | 2.0.3-3ubuntu0.1~esm1 | Fix via Ubuntu Pro ESM Apps |
| 16.04 LTS (xenial) | libwebsockets7 | 1.7.1-1ubuntu0.1~esm1 | — |
For releases from 18.04 LTS through to 26.04 LTS, the fix is only available via Ubuntu Pro through ESM Apps; a community version may arrive in future, but is not yet available. Ubuntu Pro provides up to 10 years of security coverage for over 25,000 packages in the Main and Universe repositories, and is free for up to 5 machines.
What to do
On systems with Ubuntu Pro enabled, a standard system update is all that's needed. For those without Ubuntu Pro on the affected releases, it's worth checking whether the libwebsockets package is installed (even as an indirect dependency of other services) and considering either enabling Ubuntu Pro or applying a manual update once available. Official reference: advisory USN-8893-1 at ubuntu.com/security/notices.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.