---
id: CVE-2026-103472
title: >-
  restbed through 5.0.0 accepts WebSocket frames with declared payload lengths
  up to 2^63 bytes and buffers the payload without size limits in an unbounded
  stream buffer
summary: >-
  restbed through 5.0.0 accepts WebSocket frames with declared payload lengths
  up to 2^63 bytes and buffers the payload without size limits in an unbounded
  stream buffer. Remote unauthenticated attackers can declare large frame sizes
  and s…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Corvusoft
product: restbed
affected:
  - restbed <= 5.0.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:08:43.927'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103472'
references:
  - url: 'https://github.com/Corvusoft/restbed'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/web_socket_impl.cpp#L117
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Corvusoft/restbed/issues/558'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/restbed-through-5.0.0-websocket-memory-exhaustion-via-unbounded-frame-buffering
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T18:17:24.548Z'
---

## Overview

restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
