Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44545

Опубликовано: 03 июн. 2026
Источник: debian
EPSS Низкий

Описание

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-daphnefixed4.2.2-0.1package
python-daphnefixed4.1.2-2+deb13u1trixiepackage
python-daphneno-dsabookwormpackage
python-daphnepostponedbullseyepackage

Примечания

  • Fixed by: https://github.com/django/daphne/commit/32f8be0fb0bf2a441085cb45e0e8f45455f0793e (4.2.2)

EPSS

Процентиль: 24%
0.00328
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 7.5
redhat
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
nvd
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
github
2 месяца назад

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

EPSS

Процентиль: 24%
0.00328
Низкий