Java Websocket Project maintains a WebSocket implementation library for Java, a focused component that, despite its narrow product scope, provides protocol-level functionality used across a variety of server and client applications. The vulnerability surface observed on this vendor centers on its core WebSocket library and reflects the parsing and state-management complexity inherent to protocol implementations. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Java Websocket Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11050HIGH In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. Thi | May 7, 2020 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Java Websocket Project.
Media articles that mention a CVE ID that affects a product developed by Java Websocket Project — matched by CVE ID, not by vendor name.