QID 981271

QID 981271: Python (pip) Security Update for websockets (GHSA-6g87-ff9q-v847)

The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-6g87-ff9q-v847 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981271

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6g87-ff9q-v847 websockets URL Logo github.com/advisories/GHSA-6g87-ff9q-v847