Beveiligingsadvies

CVE-2026-44545

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-03 13:17:42
Laatst bijgewerkt 2026-06-03 15:48:40
Toegewezen door DSF
CVSS-score 5.3
Status PUBLISHED

Beschrijving

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.