CVE-2026-103472
Received Received - Intake

Memory Exhaustion via Unbounded WebSocket Frames in restbed

Vulnerability report for CVE-2026-103472, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
restbed restbed to 5.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in restbed through version 5.0.0 involves improper handling of WebSocket frames. Attackers can send frames with declared payload lengths up to 2^63 bytes. The server attempts to buffer these payloads without size limits, leading to excessive memory consumption and potential denial of service through process crashes.

Detection Guidance

Monitor for unusually large WebSocket frame sizes or memory exhaustion events in restbed applications. Check server logs for WebSocket connection attempts with payload lengths exceeding normal limits. Use network monitoring tools to detect abnormally large data streams targeting WebSocket ports.

Impact Analysis

This vulnerability allows remote unauthenticated attackers to crash the server by sending large WebSocket payloads. This can disrupt service availability, cause downtime, and require manual intervention to restore normal operations.

Mitigation Strategies

Upgrade restbed to a patched version if available. Implement input validation to reject WebSocket frames with payload lengths exceeding reasonable limits. Configure network firewalls to block or rate-limit WebSocket traffic from untrusted sources. Monitor memory usage and set up alerts for potential exhaustion events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103472. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart