High severity7.5NVD Advisory· Published Feb 28, 2020· Updated Jun 17, 2026
CVE-2018-21035
CVE-2018-21035
Description
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
Affected products
4- Qt/Qtdescription
- osv-coords2 versions
< 5.12.5-6.el8+ 1 more
- (no CPE)range: < 5.12.5-6.el8
- (no CPE)range: < 5.12.5-2.el8
Patches
Vulnerability mechanics
References
2- codereview.qt-project.org/c/qt/qtwebsockets/+/284735nvdPatchThird Party Advisory
- bugreports.qt.io/browse/QTBUG-70693nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.