Home

Description

An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive information or cause unexpected server behavior via the websocket_server/websocket_server.py, WebSocketServer._message_received components.

PUBLISHED Reserved 2025-12-08 | Published 2026-01-20 | Updated 2026-01-21 | Assigner mitre

References

github.com/...rinvest211/websocket-server-vuln-poc/tree/main

cve.org (CVE-2025-66902)

nvd.nist.gov (CVE-2025-66902)

Download JSON