A vulnerability described as problematic has been identified in warmcat libwebsockets up to 4.3.6/4.4.2. This affects the function
lws_upng_emit_next_line
of the component PNG File Parser. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2025-11679. It is possible to launch the attack remotely. No exploit is available.