PT-2026-45940 · Daphne · Daphne
Carlton Gibson
+1
·
Published
2026-06-03
·
Updated
2026-06-03
·
CVE-2026-44545
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
daphne versions prior to 4.2.2
Description
An unauthenticated remote attacker can cause excessive memory consumption and a denial of service by sending arbitrarily large WebSocket messages or frames. This occurs because
maxFramePayloadSize and maxMessagePayloadSize are not passed to Autobahn's WebSocketServerFactory function, which defaults both values to 0, meaning they are unlimited.Recommendations
Update to version 4.2.2 or later.
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daphne