Back

HIGH

Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service

Published Jun 3, 2026

Description

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DSF
Published Jun 3, 2026
Updated Jun 3, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated Jun 3, 2026
NVD
Status Analyzed
Modified Jul 22, 2026
Red Hat
Severity Important
Public date Jun 3, 2026
GHSA-RRC9-MX66-FFCM