Impact
The flaw resides in the processFrameContinuousAndNonFin method of the Fragmentation Handler. By manipulating incoming frames, an attacker can trigger uncontrolled allocation of memory resources, leading to resource exhaustion or denial of service. The weakness aligns with CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Allocation of Resources Without Limits).
Affected Systems
The vulnerability affects the TooTallNate Java-WebSocket library, versions up to 1.6.1. This includes any application that incorporates the available.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score is less than 1% and the issue is not listed in CISA’s KEV catalog. The attack can be performed remotely and a public exploit has been released, suggesting a tangible risk for exposed services that use the vulnerable library. Without an official patch the risk remains until the pull request is merged and a new release issued.
OpenCVE Enrichment