MEDIUM

CVE-2026-90584

2026-09-13 CVSS v3.1
CVSS
5.3

Description

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption
CWE-770 Resource Allocation Without Limits

EPSS Score

0.42%
Probability of exploitation in next 30 days
35.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE