Skip to content

fix(deps): Integer overflow in websocket #352

Closed
kreeksec wants to merge 1 commit intobuzzfeed:mainfrom
kreeksec:patch-1
Closed

fix(deps): Integer overflow in websocket #352
kreeksec wants to merge 1 commit intobuzzfeed:mainfrom
kreeksec:patch-1

Conversation

@kreeksec
Copy link
Copy Markdown

Problem

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

@danbf
Copy link
Copy Markdown
Contributor

danbf commented Feb 7, 2025

handling in #353 since newer package versions have come out

@kreeksec kreeksec closed this by deleting the head repository Jun 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants