Safety vulnerability ID: 42249
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Websockets 5.0 includes a fix for CVE-2018-1000518: aaugustin websockets version 4 contains a CWE-409 -Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via sending a specially crafted frame on an established connection.
https://github.com/aaugustin/websockets/pull/407
Latest version: 14.1
An implementation of the WebSocket Protocol (RFC 6455 & 7692)
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application