Resource exhaustion in ws - CVE-2026-48779
Published: May 25, 2026
ws
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the WebSocket message handling logic when processing a high volume of exceptionally small fragments and data chunks. A remote attacker can send a large number of tiny fragmented messages to cause a denial of service.
The issue can lead to process termination due to out-of-memory conditions.