Improper Handling of Highly Compressed Data in aaugustin Websockets
CVE-2018-1000518
7.5HIGH
What is CVE-2018-1000518?
The aaugustin websockets, specifically version 4, contains a vulnerability that stems from improper handling of highly compressed data, which can lead to Denial of Service through memory exhaustion. This vulnerability occurs unless the configuration is set to compression=None. Attackers can exploit this flaw by sending specially crafted frames on an established connection, potentially crashing services and affecting availability. Users are encouraged to upgrade to version 5 where this issue has been addressed.