CVE-2026-31903 describes a critical lack of rate limiting in the WebSocket Application Programming Interface for authentication requests, potentially affecting various systems utilizing this API. Rated High severity (CVSS 7.5), this vulnerability allows remote attackers with low complexity to conduct denial-of-service attacks or brute-force unauthorized access. The primary impact is a high availability risk, with no direct confidentiality or integrity compromise. There is currently no evidence of active exploitation, nor is public exploit code available. While it has received minimal community attention, it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:igl:eparking.fi:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.