Allocation of Resources Without Limits or Throttling Affecting crossbar package, versions [,26.7.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.52% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-CROSSBAR-20046663
  • published22 Sept 2026
  • disclosed18 Sept 2026
  • creditBrian

Introduced: 18 Sep 2026

NewCVE-2026-77528  (opens in a new tab)
CWE-409  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade crossbar to version 26.7.1 or higher.

Overview

crossbar is a Crossbar.io multi-protocol (WAMP/WebSocket, REST/HTTP, MQTT) application router for microservices.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the onFrameData function in protocol.py, where the maxMessagePayloadSize limit is enforced against the compressed wire size of a permessage-compressed WebSocket frame rather than the uncompressed (inflated) application-level payload. An attacker can send a small compressed WebSocket frame that inflates far beyond the configured limit, bypassing the size check and delivering an oversized payload to the application, which can crash or exhaust resources in the receiving process.

CVSS Base Scores

version 4.0
version 3.1