Lucene search

K
osvGoogleOSV:GHSA-6G87-FF9Q-V847
HistorySep 17, 2018 - 8:46 p.m.

websockets is vulnerable to denial of service by memory exhaustion

2018-09-1720:46:52
Google
osv.dev
12

0.001 Low

EPSS

Percentile

45.6%

The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appears to be exploitable via sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in version 5.0

CPENameOperatorVersion
websocketseq4.0.1
websocketseq4.0

0.001 Low

EPSS

Percentile

45.6%