Description
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0146 | aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5. |
Github GHSA |
GHSA-6g87-ff9q-v847 | websockets is vulnerable to denial of service by memory exhaustion |
References
| Link | Providers |
|---|---|
| https://github.com/aaugustin/websockets/pull/407 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:40:47.112Z
Reserved: 2018-05-19T00:00:00.000Z
Link: CVE-2018-1000518
No data.
Status : Modified
Published: 2018-06-26T16:29:01.243
Modified: 2024-11-21T03:40:06.297
Link: CVE-2018-1000518
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA