{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-09T10:22:39.454","vulnerabilities":[{"cve":{"id":"CVE-2025-1866","sourceIdentifier":"cve_disclosure@tech.gov.sg","published":"2025-03-03T09:15:39.370","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading to out-of-bounds memory access. This issue affects libwebsockets before 4.3.4 and is present in code built specifically for the Win32 platform.\n\nBy default, the affected code is not executed unless one of the following conditions is met:\n\nLWS_WITHOUT_EXTENSIONS (default ON) is manually set to OFF in CMake.\nLWS_WITH_HTTP_STREAM_COMPRESSION (default OFF) is manually set to ON in CMake.\nDespite these conditions, when triggered in affected configurations, this vulnerability may allow attackers to manipulate pointers, potentially leading to memory corruption or unexpected behavior."},{"lang":"es","value":"La vulnerabilidad de restricción inadecuada de operaciones dentro de los límites de un búfer de memoria en libwebsockets de warmcat permite la manipulación de punteros, lo que puede provocar un acceso a la memoria fuera de los límites. Este problema afecta a libwebsockets anteriores a la versión 4.3.4 y está presente en el código creado específicamente para la plataforma Win32. De forma predeterminada, el código afectado no se ejecuta a menos que se cumpla una de las siguientes condiciones: LWS_WITHOUT_EXTENSIONS (predeterminado ON) se configura manualmente en OFF en CMake. LWS_WITH_HTTP_STREAM_COMPRESSION (predeterminado OFF) se configura manualmente en ON en CMake. A pesar de estas condiciones, cuando se activa en las configuraciones afectadas, esta vulnerabilidad puede permitir a los atacantes manipular punteros, lo que puede provocar una corrupción de la memoria o un comportamiento inesperado. "}],"metrics":{"cvssMetricV40":[{"source":"cve_disclosure@tech.gov.sg","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"cve_disclosure@tech.gov.sg","type":"Secondary","description":[{"lang":"en","value":"CWE-119"}]}],"references":[{"url":"https://github.com/warmcat/libwebsockets/commit/3f7c79fd57338aca1bf4a1b1f24e324b80d36265","source":"cve_disclosure@tech.gov.sg"}]}}]}