VYPR
High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026

CVE-2026-50176

CVE-2026-50176

Description

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

Affected products

2
  • Cisagov/Csafreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

1