CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54465

mediumcovered by 2 sourcesfirst seen 2026-07-15
Impact If this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the WebSocket::Driver.server() method, or, if it is used to complement a WebSocket client, then a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. Patches The issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. Workarounds No known workarounds exist. Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.

⚡ Watch CVE-2026-54465

Get an email if CVE-2026-54465 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-54465

CVE.org record

Embed the live status

CVE-2026-54465 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54465 status](https://www.csirts.com/badge/CVE-2026-54465)](https://www.csirts.com/cve/CVE-2026-54465)