OSV 1.4.0 · github-reviewed · 修改于 2026-06-16 04:11
发布时间
2026-06-16 04:11
GitHub 审查时间
2026-06-16 04:11
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-xcgm-r5h9-7989/GHSA-xcgm-r5h9-7989.json
If an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use.
If a web application has WebSocket endpoints, it may be possible for an attacker to execute a DoS attack through excessive memory use.
Patch: https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d