CVE-2026-54466Critical▾ Midnightwebsocket-driver: Message corruption via abuse of protocol length headers
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer. Since JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly.
The issue has been patched in version 0.7.5 by rejecting the message if the length header exceeds the configured maximum message length. All users should upgrade to this version.
No known workarounds exist.
This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
websocket-driver < 0.7.5Upgrade to a patched release:
websocket-driver 0.7.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression
CVE-2026-61666High· 7.5websocket-driver is a WebSocket protocol handler with pluggable I/O
CVE-2026-54463Mediumwebsocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression
CVE-2026-54465Mediumwebsocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-5367High· 8.6A flaw was found in OVN (Open Virtual Network)