daphne vulnerabilities
CVEs whose affected-version data names the daphne package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-44546Low· 3.7daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
▾ Sunlitdaphne · daphneEPSS 0.17%via OSV
CVE-2026-44545Medium· 5.3daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames
daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames
▾ Sunlitdaphne · daphneEPSS 0.33%via OSV