Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19204

Опубликовано: 07 сент. 2026
Источник: nvd
EPSS Низкий

Описание

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap.

This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

EPSS

Процентиль: 22%
0.00293
Низкий

Дефекты

CWE-770

Связанные уязвимости

ubuntu
14 дней назад

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

debian
14 дней назад

A client may send a WebSocket frame with an unknown opcode and a very ...

github
14 дней назад

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

EPSS

Процентиль: 22%
0.00293
Низкий

Дефекты

CWE-770