PT-2026-45940 · Daphne · Daphne

Carlton Gibson

+1

·

Published

2026-06-03

·

Updated

2026-06-03

·

CVE-2026-44545

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions daphne versions prior to 4.2.2
Description An unauthenticated remote attacker can cause excessive memory consumption and a denial of service by sending arbitrarily large WebSocket messages or frames. This occurs because maxFramePayloadSize and maxMessagePayloadSize are not passed to Autobahn's WebSocketServerFactory function, which defaults both values to 0, meaning they are unlimited.
Recommendations Update to version 4.2.2 or later.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-44545

Affected Products

Daphne