High severity7.5NVD Advisory· Published Sep 30, 2026· Updated Sep 30, 2026
CVE-2026-103472
CVE-2026-103472
Description
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.