WebSocket Transport Vulnerability in Centrifugo Real-Time Messaging Server
CVE-2026-62963
8.7HIGH
What is CVE-2026-62963?
Centrifugo, a popular open-source real-time messaging server, contains a vulnerability affecting its unidirectional WebSocket transport. Prior to version 6.8.4, the server improperly enforced message size limits on compressed data. As a result, unauthenticated requests to the /connection/uni_websocket endpoint could lead to excessive memory usage and CPU consumption, potentially impacting performance and availability. This issue was addressed in version 6.8.4, emphasizing the importance of maintaining up-to-date software to mitigate security risks.
Affected Version(s)
centrifugo < 6.8.4
