PT-2023-28913 · Unknown · Tungstenite

·

CVE-2023-43669

·

Published

2023-09-20

·

Updated

2024-02-16

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tungstenite crate versions prior to 0.20.1
Description The issue allows remote attackers to cause a denial of service, resulting in minutes of CPU consumption, via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted and the average amount of data for each parse attempt.
Recommendations For versions prior to 0.20.1, update to version 0.20.1 or later to resolve the issue. As a temporary workaround, consider restricting the length of HTTP headers in client handshakes to prevent excessive CPU consumption.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-43669
GHSA-58J9-J2FJ-V8F4
GHSA-9MCR-873M-XCXP
RUSTSEC-2023-0065

Affected Products

Tungstenite