HIGH 8.7 NVD
CVE-2026-103472
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.
References
- https://github.com/Corvusoft/restbed
- https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/cor
- https://github.com/Corvusoft/restbed/issues/558
- https://www.vulncheck.com/advisories/restbed-through-5.0.0-websocket-memory-exhaustion-via
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.