CVE-2026-54465Medium▾ Sunlitwebsocket-driver: Memory exhaustion in HTTP header parser
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
If this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the WebSocket::Driver.server() method, or, if it is used to complement a WebSocket client, then a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory.
The issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version.
No known workarounds exist.
This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
websocket-driver < 0.8.1Upgrade to a patched release:
websocket-driver 0.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54463Mediumwebsocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression
CVE-2026-61666High· 7.5websocket-driver is a WebSocket protocol handler with pluggable I/O
CVE-2026-54466Criticalwebsocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression
CVE-2020-3563High· 8.6A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device