Resource Allocation Issue in TooTallNate Java-WebSocket Component
CVE-2026-90584
Key Information:
- Vendor
Tootallnate
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90584?
A vulnerability exists in the TooTallNate Java-WebSocket library where improper handling in the Fragmentation Handler's processFrameContinuousAndNonFin function allows remote attackers to exploit resource allocation issues. This weakness could be manipulated to exhaust resources, leading to service disruptions. The exploit for this vulnerability is publicly accessible, raising concerns for users of the affected Java-WebSocket versions. A pull request addressing the issue is under review.
Affected Version(s)
Java-WebSocket 1.6.0
Java-WebSocket 1.6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
