PT-2026-60379 · Debian+5 · Websocket-Driver-Ruby+1

CVE-2026-54464

·

Published

2026-07-15

·

Updated

2026-08-01

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions (affected versions not specified)
Description When used with the permessage-deflate extension, a WebSocket server or client may accept messages exceeding the configured maximum size. This occurs because the size limit is validated against the compressed data length in the message frames' headers rather than the size after decompression, potentially leading to excessive resource usage.
Recommendations Update to version 0.8.1.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54464
GHSA-33PH-FCCM-39PJ
OESA-2026-3218

Affected Products

Websocket-Driver-Ruby
Websocket-Driver