Skip to content
High Risk Denial of Service Vulnerability in Fedora 44 libwebsockets

High Risk Denial of Service Vulnerability in Fedora 44 libwebsockets

First seen 27 Jul 2026, 08:31 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 28, 2026 at 07:47 UTC
  • CVE-2026-10650 poses a high risk of Denial of Service in Fedora 44 libwebsockets.
  • The vulnerability allows resource consumption via the SSH Protocol Handler.
  • Users should upgrade to libwebsockets version 4.5.8 to mitigate the risk.

A critical Denial of Service (DoS) vulnerability has been identified in the libwebsockets library used in Fedora 44. The vulnerability, tracked as CVE-2026-10650, allows attackers to exploit the SSH Protocol Handler, leading to resource consumption issues. This could potentially disrupt services for users of Fedora 44 and earlier versions. The vulnerability was published on June 2, 2026, and affects systems utilizing libwebsockets version 4.5.7 and earlier. Users are advised to upgrade to version 4.5.8 to mitigate the risk. The patch is available through the 'dnf' update program. The issue has been classified as high risk due to its potential impact on system availability. Security professionals are urged to audit Linux privileges to limit possible exploitation. The current status indicates that the patch has been released and is available for installation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-06-02
CVE-2026-10650 published
A Denial of Service vulnerability in libwebsockets was disclosed, affecting multiple versions.
Linuxsecurity
2026-07-18
libwebsockets version 4.5.8 released
An update to libwebsockets was released to address the identified DoS vulnerability.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-10650 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed