Описание
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
A flaw was found in daphne. An unauthenticated remote attacker could exploit this vulnerability by sending arbitrarily large WebSocket messages or frames. This oversight in payload size handling can lead to excessive memory consumption, resulting in a denial of service (DoS) for the affected system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/controller-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/controller-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2 | automation-controller | Affected | ||
| Red Hat Ansible Automation Platform 2 | python3.11-daphne | Affected | ||
| Red Hat Ansible Automation Platform 2 | python3x-daphne | Affected | ||
| Red Hat Ansible Automation Platform 2 | python-daphne | Not affected | ||
| Red Hat Ansible Automation Platform 2.5 for RHEL 8 | python3.12-daphne | Fixed | RHSA-2026:50319 | 04.08.2026 |
| Red Hat Ansible Automation Platform 2.5 for RHEL 9 | python3.12-daphne | Fixed | RHSA-2026:50319 | 04.08.2026 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | python3.12-daphne | Fixed | RHSA-2026:50336 | 04.08.2026 |
| Red Hat Ansible Automation Platform 2.5 | ansible-automation-platform-25/lightspeed-rhel8 | Fixed | RHSA-2026:50357 | 04.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayl ...
daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames
EPSS
7.5 High
CVSS3