High Risk Denial of Service Vulnerability in Fedora 44 libwebsockets

High Risk Denial of Service Vulnerability in Fedora 44 libwebsockets

First seen 27 Jul 2026, 08:31 UTC Linuxsecurity 96% similarity 69.2

Article Content

Browse articles
ThreatCluster

A critical Denial of Service (DoS) vulnerability has been identified in the libwebsockets library used in Fedora 44. The vulnerability, tracked as CVE-2026-10650, allows attackers to exploit the SSH Protocol Handler, leading to resource consumption issues. This could potentially disrupt services for users of Fedora 44 and earlier versions. The vulnerability was published on June 2, 2026, and affects systems utilizing libwebsockets version 4.5.7 and earlier. Users are advised to upgrade to version 4.5.8 to mitigate the risk. The patch is available through the 'dnf' update program. The issue has been classified as high risk due to its potential impact on system availability. Security professionals are urged to audit Linux privileges to limit possible exploitation. The current status indicates that the patch has been released and is available for installation.

Key Points: • CVE-2026-10650 poses a high risk of Denial of Service in Fedora 44 libwebsockets. • The vulnerability allows resource consumption via the SSH Protocol Handler. • Users should upgrade to libwebsockets version 4.5.8 to mitigate the risk.

ThreatCluster AI

Timeline

2026-06-02
CVE-2026-10650 published
A Denial of Service vulnerability in libwebsockets was disclosed, affecting multiple versions.
Linuxsecurity
2026-07-18
libwebsockets version 4.5.8 released
An update to libwebsockets was released to address the identified DoS vulnerability.
Linuxsecurity

Community

Browse all →