Home

Description

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.

PUBLISHED Reserved 2026-05-06 | Published 2026-06-03 | Updated 2026-06-03 | Assigner DSF




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-770 (Allocation of Resources Without Limits or Throttling)

Product status

Default status
unaffected

4.2.0 (python)
affected

4.2.2 (python)
unaffected

Timeline

2026-04-18:Initial report received.
2026-05-06:Vulnerability confirmed.

Credits

ParkHyunWoo reporter

Carlton Gibson remediation developer

References

github.com/django/daphne/blob/main/CHANGELOG.txt release-notes

cve.org (CVE-2026-44545)

nvd.nist.gov (CVE-2026-44545)

Download JSON