Allocation of Resources Without Limits or Throttling in Crow - #VU147368
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in WebSocket fragmented-message handling when processing fragmented WebSocket messages. A remote attacker can send an oversized message as individually permitted fragments to cause a denial of service.
The issue affects applications that use max_payload() or websocket_max_payload() as a resource-control boundary.