PT-2026-45940 · Daphne · Daphne

·

CVE-2026-44545

·

Published

2026-06-03

·

Updated

2026-06-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions daphne versions prior to 4.2.2
Description An unauthenticated remote attacker can cause excessive memory consumption and a denial of service by sending arbitrarily large WebSocket messages or frames. This occurs because maxFramePayloadSize and maxMessagePayloadSize are not passed to Autobahn's WebSocketServerFactory function, which defaults both values to 0, meaning they are unlimited.
Recommendations Update to version 4.2.2 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44545
GHSA-RRC9-MX66-FFCM
PYSEC-2026-213
RHSA-2026:50319
RHSA-2026:50336

Affected Products

Daphne