Skip to content

Security Update

Compare
Choose a tag to compare
@boazsegev boazsegev released this 17 May 22:32
· 56 commits to master since this release

v. 0.7.1

Security: a heap-overflow vulnerability was fixed in the WebSocket parser. This attack could have been triggered remotely by a maliciously crafted message-header. Credit to Dane (4cad@silvertoque) for exposing this issue and providing a Python script demonstrating the attack.