Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)0.20%—Utcp-gqlAIUtcp-websocketAI27/9/202630/9/2026
utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL…
Pendiente de análisisAlta (7.5)0.76%—Quarkus-websockets-nextAI17/9/202622/9/2026
A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space,…
Pendiente de análisisCrítica (9.8)0.65%—LibwebsocketsAI15/9/202618/9/2026
libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AplazadaMedia (5.5)0.72%—Tootallnate Java-websocketAI13/9/202614/9/2026
A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The…
AplazadaMedia (5.5)0.40%—Warmcat LibwebsocketsAI24/8/202624/8/2026
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is…
Pendiente de análisisAlta (8.9)0.45%—Faye Websocket-driverAI17/8/202610/9/2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does…
AplazadaMedia (6.3)0.45%—Websocket DriverAI17/7/202623/7/2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size because the limit is checked against the message…
AnalizadaCrítica (9.2)0.38%—Faye Websocket-driver17/7/20266/8/2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with…
AnalizadaMedia (6.3)0.49%—Faye Websocket-driver17/7/20266/8/2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by…
AplazadaMedia (6.3)0.45%—WebsocketsAI17/7/202623/7/2026
### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size. This is because this limit is checked against the message frames' length headers, which give the size of the…
AnalizadaMedia (6.9)0.49%—Faye Websocket-driver17/7/20266/8/2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80…
AplazadaMedia (5.5)0.43%—Warmcat LibwebsocketsAI2/6/202622/7/2026
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched…
AnalizadaAlta (7.5)0.42%—Pithikos Websocket Server20/1/202617/6/2026
An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive information or cause unexpected server behavior via the websocket_server/websocket_server.py, WebSocketServer._message_received components.
AplazadaMedia (5.9)0.39%—Warmcat LibwebsocketsAI20/10/202517/6/2026
Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG…
AplazadaAlta (7.5)0.29%—Warmcat LibwebsocketsAI20/10/202517/6/2026
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the…
AplazadaMedia (6.3)0.40%—Warmcat LibwebsocketsAI20/10/202517/6/2026
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
AplazadaMedia (5.9)0.39%—Warmcat LibwebsocketsAI20/10/202530/9/2026
Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file…
AplazadaCrítica (10)0.43%—Warmcat LibwebsocketsAI3/3/202517/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading to out-of-bounds memory access. This issue affects libwebsockets before 4.3.4 and is present in code built specifically for the Win32 platform. By default, the…
ModificadaCrítica (9)0.27%—Home-assistantHome-assistant-js-websocket19/10/202317/6/2026
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized…
ModificadaAlta (7.5)0.78%—Fastify Websocket8/11/202217/6/2026
@fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a specific, malformed packet is sent. All versions of fastify-websocket are also impacted. That module is deprecated, so it will not be patched. This has been patched in version 7.1.1 (fastify v4) and…
ModificadaAlta (7.5)1.9%—Rust-websocket Project Rust-websocketFedoraproject Fedora1/8/202217/6/2026
Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would allocate a buffer based on the declared…
ModificadaAlta (8.8)1.5%—Uwebsockets Project Uwebsockets1/7/202117/6/2026
uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTree::unsubscribeAll). NOTE: the vendor's position is that this is "a minor issue or not even an issue at all" because the developer of an application (that uses uWebSockets) should not be allowing the…
ModificadaMedia (5.9)2.3%—Websockets Project WebsocketsOracle Communications Cloud Native Core PolicyOracle Communications Cloud Native Core Security Edge Protection ProxyOracle Communications Cloud Native Core Service Communication Proxy+16/6/202117/6/2026
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
ModificadaAlta (7.5)2.1%—Gorillatoolkit WebsocketDebian Linux2/12/202017/6/2026
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
ModificadaAlta (8.7)1.1%—Faye-websocket Project Faye-websocket31/7/202017/6/2026
In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement…