Vulnerabilities > Websockets Project

DATE CVE VULNERABILITY TITLE RISK
2021-06-06 CVE-2021-33880 Information Exposure Through Discrepancy vulnerability in multiple products
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...).
network
high complexity
websockets-project oracle CWE-203
5.9
2018-06-26 CVE-2018-1000518 Resource Exhaustion vulnerability in Websockets Project Websockets 4.0
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion.
network
low complexity
websockets-project CWE-400
7.5