CVE-2026-97363

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

  • Published Oct 2, 2026
  • CVSS 8.7 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-97363 at the National Vulnerability Database