CVE-2026-44545

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

Beschreibung

Daphne vor Version 4.2.2 übertrug die Werte für maxFramePayloadSize und maxMessagePayloadSize nicht an Autobahns WebSocketServerFactory. Da Autobahn beide Werte standardmäßig auf 0 (unbegrenzt) setzt, könnte ein unauthentifizierter Fernangreifer beliebig große WebSocket-Nachrichten oder -Frames senden, was zu übermäßigem Speicherverbrauch und einem Denial-of-Service führt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
25.6 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.3 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 17:56 UTC
CWE-770

Weakness-Klassen (CWE)

  • CWE-770Base

    Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-22 19:10 UTC· nvd@nist.gov
    • Translation: Title: daphne de djangoproject, Description: daphne antes de la versión 4.2.2 no pasaba maxFramePayloadSize ni maxMessagePayloadSize a la WebSocketServerFactory de Autobahn. Debido a que Autobahn establece ambos valores por defecto en 0 (ilimitado), un atacante remoto no autenticado podría enviar mensajes o tramas WebSocket arbitrariamente grandes, causando un consumo excesivo de memoria y una denegación de servicio.
  2. Initial Analysis2026-06-15 19:53 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CPE Configuration: OR *cpe:2.3:a:djangoproject:daphne:*:*:*:*:*:*:*:* versions up to (excluding) 4.2.2
    • Reference Type: Django Software Foundation: https://github.com/django/daphne/blob/main/CHANGELOG.txt Types: Release Notes

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / pyasn1jammy

  • linux

    ubuntu / pyasn1noble

  • linux

    ubuntu / pyasn1resolute

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    django6.0.0

  • djangoproject

    daphne4.2.2

  • js-cookie

    javascript_cookie3.0.7

  • npm

    tmp

  • npm

    webpack-dev-server

  • pyopenssl

    pyopenssl22.0.0 – 26.0.0

  • pypi

    aiohttp0.1

  • pypi

    aiohttp0.10.0

  • pypi

    aiohttp0.10.1

  • pypi

    aiohttp0.10.2

  • pypi

    aiohttp0.11.0

  • pypi

    aiohttp0.12.0

  • pypi

    aiohttp0.13.0

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-44545