CVE-2018-1000518

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
26/06/2018
Last modified:
10/02/2022

Description

aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:websockets_project:websockets:4.0:*:*:*:*:python:*:*


References to Advisories, Solutions, and Tools