Medium severity5.3NVD Advisory· Published Jun 3, 2026· Updated Jul 22, 2026
CVE-2026-44545
CVE-2026-44545
Description
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
daphnePyPI | < 4.2.2 | 4.2.2 |
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:djangoproject:daphne:*:*:*:*:*:*:*:*range: <4.2.2
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.