Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44545

Опубликовано: 03 июн. 2026
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
EPSS Низкий

Описание

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:djangoproject:daphne:*:*:*:*:*:*:*:*
Версия до 4.2.2 (исключая)

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 7.5
redhat
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
debian
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayl ...

CVSS3: 5.3
github
2 месяца назад

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-770