A vulnerability classified as critical was found in warmcat libwebsockets up to 4.3.6/4.4.2. Affected is the function lws_handshake_server. Such manipulation leads to use after free.

This vulnerability is uniquely identified as CVE-2025-11677. The attack can be launched remotely. No exploit exists.