Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c68q-h477-5646

Опубликовано: 03 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

EPSS

Процентиль: 40%
0.00491
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
redhat
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
nvd
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
debian
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Beca ...

CVSS3: 3.1
fstec
около 2 месяцев назад

Уязвимость компонента WebSocket библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 40%
0.00491
Низкий

7.5 High

CVSS3

Дефекты

CWE-770