Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44545

Опубликовано: 03 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

A flaw was found in daphne. An unauthenticated remote attacker could exploit this vulnerability by sending arbitrarily large WebSocket messages or frames. This oversight in payload size handling can lead to excessive memory consumption, resulting in a denial of service (DoS) for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/controller-rhel9Affected
Red Hat Ansible Automation Platform 2automation-controllerAffected
Red Hat Ansible Automation Platform 2python3.11-daphneAffected
Red Hat Ansible Automation Platform 2python3x-daphneAffected
Red Hat Ansible Automation Platform 2python-daphneNot affected
Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-daphneFixedRHSA-2026:5031904.08.2026
Red Hat Ansible Automation Platform 2.5 for RHEL 9python3.12-daphneFixedRHSA-2026:5031904.08.2026
Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-daphneFixedRHSA-2026:5033604.08.2026
Red Hat Ansible Automation Platform 2.5ansible-automation-platform-25/lightspeed-rhel8FixedRHSA-2026:5035704.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2484377daphne: daphne: Denial of Service via excessive WebSocket message size

EPSS

Процентиль: 25%
0.00328
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
nvd
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

CVSS3: 5.3
debian
2 месяца назад

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayl ...

CVSS3: 5.3
github
2 месяца назад

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

EPSS

Процентиль: 25%
0.00328
Низкий

7.5 High

CVSS3