HIGH7.5
PYSEC-2026-213
Quick fix
PYSEC-2026-213 — daphne: upgrade to the fixed version with the command below.
pip install --upgrade 'daphne>=4.2.2'Details
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
Are you affected?
Enter the version of the package you're using.