A vulnerability classified as critical has been found in warmcat libwebsocket up to 4.3.6/4.4.2. This impacts the function lws_adns_parse_label. This manipulation causes stack-based buffer overflow.

This vulnerability is handled as CVE-2025-11678. The attack can be initiated remotely. There is not any exploit available.