Export limit exceeded: 400540 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400540 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103472 | 1 Corvusoft | 1 Restbed | 2026-10-01 | 7.5 High |
| restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash. | ||||
| CVE-2026-103471 | 1 Corvusoft | 1 Restbed | 2026-10-01 | 7.5 High |
| restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed. | ||||
Page 1 of 1.