QID 981271
QID 981271: Python (pip) Security Update for websockets (GHSA-6g87-ff9q-v847)
The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6g87-ff9q-v847 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6g87-ff9q-v847 -
github.com/advisories/GHSA-6g87-ff9q-v847
CVEs related to QID 981271
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6g87-ff9q-v847 | websockets |
|