CVE-2026-103472 Details
Description
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.
A denial-of-service vulnerability has been identified in Corvusoft Restbed versions through 5.0.0. This issue arises because the framework accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload in an unbounded stream. Remote unauthenticated attackers can exploit this by declaring large frame sizes, which leads to excessive memory consumption and process crashes on the server.
To address this vulnerability, set a finite default maximum frame size for WebSocket payloads, such as 16 megabytes. Additionally, implement a maximum buffer size for HTTP requests to prevent unbounded memory consumption.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Corvusoft restbed | <= 5.0.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion