📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Data Centers and Critical Infrastructure CRITICAL 19m Global general Enterprise Security and Governance HIGH 27m Global phishing General Public / Multiple Sectors HIGH 42m Global vulnerability Windows Systems and Enterprise IT CRITICAL 43m Global vulnerability Information Technology HIGH 54m Global general Information Technology and Cybersecurity HIGH 1h Global vulnerability Cybersecurity Services HIGH 1h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Enterprise Software and Cloud Services HIGH 2h Global vulnerability Software/Technology CRITICAL 2h Global vulnerability Data Centers and Critical Infrastructure CRITICAL 19m Global general Enterprise Security and Governance HIGH 27m Global phishing General Public / Multiple Sectors HIGH 42m Global vulnerability Windows Systems and Enterprise IT CRITICAL 43m Global vulnerability Information Technology HIGH 54m Global general Information Technology and Cybersecurity HIGH 1h Global vulnerability Cybersecurity Services HIGH 1h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Enterprise Software and Cloud Services HIGH 2h Global vulnerability Software/Technology CRITICAL 2h Global vulnerability Data Centers and Critical Infrastructure CRITICAL 19m Global general Enterprise Security and Governance HIGH 27m Global phishing General Public / Multiple Sectors HIGH 42m Global vulnerability Windows Systems and Enterprise IT CRITICAL 43m Global vulnerability Information Technology HIGH 54m Global general Information Technology and Cybersecurity HIGH 1h Global vulnerability Cybersecurity Services HIGH 1h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Enterprise Software and Cloud Services HIGH 2h Global vulnerability Software/Technology CRITICAL 2h
Vulnerabilities

CVE-2026-10650

Medium
CWE-400 — Weakness Type
Published: Jun 2, 2026  ·  Modified: Jun 5, 2026  ·  Source: NVD
CVSS v3
5.3
🔗 NVD Official
📄 Description (English)

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

🤖 AI Executive Summary

CVE-2026-10650 is a medium-severity denial-of-service vulnerability in libwebsockets SSH protocol handler affecting versions up to 4.5.8. A remote attacker can manipulate the msg_len argument to cause excessive resource consumption, potentially disrupting SSH-based services. While a patch commit exists, official releases may not yet include the fix, requiring immediate assessment of affected deployments.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 4, 2026 07:01
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi organizations using libwebsockets for SSH-based remote access and management: (1) Government agencies and NCA infrastructure relying on SSH for secure administration; (2) Banking sector (SAMA-regulated) using SSH for secure inter-bank communications and critical system management; (3) Energy sector (ARAMCO, SEC) utilizing SSH for SCADA and industrial control system access; (4) Telecom operators (STC, Mobily, Zain) managing network infrastructure via SSH; (5) Healthcare institutions using SSH for secure data transmission. The DoS impact could disrupt critical administrative access during operational hours.
🏢 Affected Saudi Sectors
Government Banking Energy Telecommunications Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all systems using libwebsockets versions ≤4.5.8, particularly those with SSH protocol handler enabled
2. Assess if SSH functionality is actively used; disable if not required
3. Implement network-level rate limiting on SSH ports (22, custom SSH ports)
4. Enable SSH connection logging and monitor for abnormal msg_len values

Patching Guidance:
1. Apply commit 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498 from libwebsockets repository if building from source
2. Monitor for official libwebsockets 4.5.9+ release and upgrade immediately upon availability
3. Test patches in non-production environments first

Compensating Controls:
1. Implement SSH access controls via firewall rules (whitelist trusted IPs)
2. Deploy IDS/IPS rules to detect malformed SSH protocol messages with abnormal msg_len values
3. Configure SSH connection timeouts and resource limits (MaxStartups, MaxSessions)
4. Monitor system resource utilization (CPU, memory) for anomalies during SSH sessions
5. Implement SSH key-based authentication only; disable password authentication

Detection Rules:
1. Alert on SSH connections with unusually large msg_len values in protocol parsing
2. Monitor for sustained high CPU/memory usage correlating with SSH connections
3. Track failed SSH authentication attempts and connection resets
4. Log and alert on libwebsockets error messages related to SSH protocol parsing
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع الأنظمة التي تستخدم إصدارات libwebsockets ≤4.5.8، خاصة تلك التي تفعّل معالج بروتوكول SSH
2. تقييم ما إذا كانت وظيفة SSH مستخدمة بنشاط؛ تعطيلها إن لم تكن مطلوبة
3. تطبيق تحديد معدل على مستوى الشبكة على منافذ SSH (22، منافذ SSH المخصصة)
4. تفعيل تسجيل اتصالات SSH ومراقبة قيم msg_len غير الطبيعية

إرشادات التصحيح:
1. تطبيق التزام 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498 من مستودع libwebsockets عند البناء من المصدر
2. مراقبة إصدار libwebsockets 4.5.9+ الرسمي والترقية فوراً عند توفره
3. اختبار التصحيحات في بيئات غير الإنتاج أولاً

الضوابط البديلة:
1. تطبيق ضوابط الوصول إلى SSH عبر قواعد جدار الحماية (قائمة بيضاء للعناوين الموثوقة)
2. نشر قواعد IDS/IPS للكشف عن رسائل بروتوكول SSH المشوهة بقيم msg_len غير طبيعية
3. تكوين مهلات اتصال SSH وحدود الموارد (MaxStartups، MaxSessions)
4. مراقبة استخدام موارد النظام (CPU، الذاكرة) للشذوذ أثناء جلسات SSH
5. تطبيق مصادقة SSH القائمة على المفاتيح فقط؛ تعطيل مصادقة كلمة المرور

قواعد الكشف:
1. تنبيه على اتصالات SSH بقيم msg_len كبيرة بشكل غير عادي في تحليل البروتوكول
2. مراقبة استخدام CPU/الذاكرة المرتفع المستمر المرتبط باتصالات SSH
3. تتبع محاولات مصادقة SSH الفاشلة وإعادة تعيين الاتصالات
4. تسجيل والتنبيه على رسائل خطأ libwebsockets المتعلقة بتحليل بروتوكول SSH
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.2.1 - Change management procedures ECC 2024 A.14.2.1 - Secure development policy
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.IP-12 - Security patch management DE.CM-8 - Vulnerability scans and assessments
🟡 ISO 27001:2022
A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy A.12.2.1 - Change management
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and updates Requirement 11.2 - Vulnerability scanning
📊 CVSS Score
5.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score5.3
CWECWE-400
EPSS0.06%
Exploit No
Patch ✗ No
Published 2026-06-02
Source Feed nvd
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-400
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.