VYPR

Restbed

by Corvusoft

CVEs (2)

  • CVE-2026-103472HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server…

  • CVE-2026-103471HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the…