Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c68q-h477-5646

Опубликовано: 03 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

EPSS

Процентиль: 48%
0.00609
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
redhat
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
nvd
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

msrc
около 1 месяца назад

WS Auto-PONG memory exhaustion

CVSS3: 7.5
debian
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Beca ...

EPSS

Процентиль: 48%
0.00609
Низкий

7.5 High

CVSS3

Дефекты

CWE-770