daphne是Django开源的一个支持HTTP、HTTP2和WebSocket的ASGI协议服务器。 daphne 4.2.2之前版本存在安全漏洞,该漏洞源于未传递最大帧或消息有效载荷大小,可能导致未经身份验证的远程攻击者发送任意大的WebSocket消息,造成过度内存消耗和拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| djangoproject | daphne | 4.2.0≤ 4.2.1 |
affected |
4.2.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | daphne | 4.2.0 ~ 4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44546 | 3.7 LOW | Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofi |
| CVE-2026-7666 | 3.1 LOW | Potential unencrypted email transmission via STARTTLS in the SMTP backend |
| CVE-2026-48587 | 3.1 LOW | Potential exposure of private data via whitespace padding in Vary header |
| CVE-2026-35193 | 3.1 LOW | Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddlewar |
| CVE-2026-6873 | 3.1 LOW | Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie |
| CVE-2026-8404 | 3.1 LOW | Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCa |
No comments yet