漏洞情报聚合

CVE-2026-5680 - A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application. - 漏洞详情

漏洞编号:CVE-2026-5680

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-5680

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-770

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

相关链接

相关漏洞

« 返回首页