Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrc9-mx66-ffcm

Опубликовано: 03 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
nvd
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
debian
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayl ...

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770