CVE-2025-41707
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
14/10/2025
Last modified:
03/11/2025
Description
The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue without affecting the core functionality.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



