PT-2026-60379 · Debian+5 · Websocket-Driver-Ruby+1
CVE-2026-54464
·
Published
2026-07-15
·
Updated
2026-08-01
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
(affected versions not specified)
Description
When used with the
permessage-deflate extension, a WebSocket server or client may accept messages exceeding the configured maximum size. This occurs because the size limit is validated against the compressed data length in the message frames' headers rather than the size after decompression, potentially leading to excessive resource usage.Recommendations
Update to version 0.8.1.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Websocket-Driver-Ruby
Websocket-Driver