News

USN-8893-1: two libwebsockets flaws, risk of remote code execution

Ubuntu has published security advisory USN-8893-1: two vulnerabilities in libwebsockets allow crashes or remote code execution.

UptimeMag editorial team · 7 October 2026 · 2 min read

USN-8893-1: due falle in libwebsockets, rischio esecuzione di codice

On 7 October 2026, Ubuntu published security advisory USN-8893-1, covering two vulnerabilities in the libwebsockets library, used to build WebSocket-based network applications. For anyone running servers that expose WebSocket or HTTP/2 services, the advisory calls for updating packages as soon as possible: an attacker exploiting these flaws could crash the process or, in the worst case, execute arbitrary code.

The two flaws

The first, CVE-2026-19773, concerns parsing of HTTP/2 HPACK path headers: libwebsockets fails to properly validate user-supplied data, risking a write past the end of an allocated buffer. According to the Ubuntu advisory, this can lead to arbitrary code execution.

The second, CVE-2026-78161, concerns handling of CBOR recording in the LECP parser: here too a write past the allocated buffer can occur, potentially crashing the process or allowing code execution.

Affected packages and fixed versions

The package affected is libwebsockets, in its various forms depending on the release. The fixed versions are:

Ubuntu release Package Fixed version Note
26.04 LTS (resolute) libwebsockets19t64 4.3.5-3ubuntu1.2+esm1 Fix via Ubuntu Pro ESM Apps
24.04 LTS (noble) libwebsockets19t64 4.3.3-1.1ubuntu0.1~esm3 Fix via Ubuntu Pro ESM Apps
22.04 LTS (jammy) libwebsockets16 4.0.20-2ubuntu1.1+esm2 Fix via Ubuntu Pro ESM Apps
20.04 LTS (focal) libwebsockets15 3.2.1-3ubuntu0.1~esm3 Fix via Ubuntu Pro ESM Apps
18.04 LTS (bionic) libwebsockets8 2.0.3-3ubuntu0.1~esm1 Fix via Ubuntu Pro ESM Apps
16.04 LTS (xenial) libwebsockets7 1.7.1-1ubuntu0.1~esm1 —

For releases from 18.04 LTS through to 26.04 LTS, the fix is only available via Ubuntu Pro through ESM Apps; a community version may arrive in future, but is not yet available. Ubuntu Pro provides up to 10 years of security coverage for over 25,000 packages in the Main and Universe repositories, and is free for up to 5 machines.

What to do

On systems with Ubuntu Pro enabled, a standard system update is all that's needed. For those without Ubuntu Pro on the affected releases, it's worth checking whether the libwebsockets package is installed (even as an indirect dependency of other services) and considering either enabling Ubuntu Pro or applying a manual update once available. Official reference: advisory USN-8893-1 at ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.