Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w753-5ffq-99wr

Опубликовано: 07 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap.

This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap.

This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

EPSS

Процентиль: 22%
0.00293
Низкий

8.7 High

CVSS4

Дефекты

CWE-770

Связанные уязвимости

ubuntu
14 дней назад

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

nvd
14 дней назад

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

debian
14 дней назад

A client may send a WebSocket frame with an unknown opcode and a very ...

EPSS

Процентиль: 22%
0.00293
Низкий

8.7 High

CVSS4

Дефекты

CWE-770