Resource exhaustion in ws - CVE-2026-48779
Published: May 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the WebSocket message handling logic when processing a high volume of exceptionally small fragments and data chunks. A remote attacker can send a large number of tiny fragmented messages to cause a denial of service.
The issue can lead to process termination due to out-of-memory conditions.
Affected software
Netezza Appliance
Confluence Data Center
Bitbucket Data Center
Fedora
python-jupytext
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2026-48779
Netezza Appliance - update to 1.0.2.0
Confluence Data Center - update to 9.2.5
Bitbucket Data Center - addressed in versions 9.4.23, 10.2.6, 10.4.2
python-jupytext - addressed in versions 1.19.4-1.fc43, 1.19.4-1.fc44
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
External References
Related Security Bulletins
- Resource exhaustion in ws
- Fedora 44 update for python-jupytext
- Fedora 43 update for python-jupytext
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.19
- Resource exhaustion in Confluence Data Center
- IBM Netezza Appliance update for ws
- Multiple vulnerabilities in Bitbucket Data Center