The Websockets Project maintains a specialized Python library for WebSocket protocol implementation, a narrowly scoped but widely embedded component in web applications and real-time communication systems. Observed vulnerabilities center on protocol-handling weaknesses including observable discrepancies in state management and uncontrolled resource consumption, which reflect the parsing and connection-state complexity inherent to bidirectional communication protocols. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Websockets Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000518HIGH aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with com | Jun 26, 2018 | 7.5 | 23 | NO | NO |
CVE-2021-33880MEDIUM The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(cr | Jun 6, 2021 | 5.9 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Websockets Project.
Media articles that mention a CVE ID that affects a product developed by Websockets Project — matched by CVE ID, not by vendor name.