CVE-2026-54466
CVE-2026-54466 is a critical vulnerability (CVSS 9.2) in the websocket-driver library affecting versions before 0.7.5. An attacker can send a WebSocket frame with an indefinitely long length header, causing the server to misinterpret the payload due to floating‑point precision loss. The issue is resolved in websocket-driver version 0.7.5.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of websocket-driver prior to version 0.7.5.
Real-world impact
An attacker could cause incorrect parsing of WebSocket payloads, potentially leading to unexpected behavior or bypass of security checks.
Why this severity
CVSS 9.2 reflects a network‑reachable attack with low complexity, no privileges or user interaction required, and high impact on integrity.
What to do about it
- 01Upgrade websocket-driver to version 0.7.5 or later.
Fix information comes from the NVD description which states the issue is fixed in version 0.7.5.
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.