<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:06:10.175747+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-34824</id>
    <title>CVE-2026-34824 — Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service</title>
    <updated>2026-10-02T22:06:10.177717+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> mesop-dev mesop</p>
<p>Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework. This issue has been patched in version 1.2.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-34824"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jr7-6hqp-x679</id>
    <title>GHSA-3jr7-6hqp-x679 — Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service</title>
    <updated>2026-10-02T22:06:10.177781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mesop</p>
<p>### Summary
An uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework.</p>
<p>### Details
The vulnerability stems from an architectural flaw in how incoming WebSocket messages are processed. In the `mesop/server/server.py` file, the `handle_websocket` function listens for incoming messages and immediately spawns a new `threading.Thread` for every successfully parsed `ui_request`.</p>
<p>There is no thread pool, message queue, or rate-limiting mechanism implemented to restrict the number of concurrent threads spawned per connection.</p>
<p>*Vulnerable code snippet in `mesop/server/server.py`:*
```python
while True:
    message = ws.receive()
    if not message:
        continue
    # ... message parsing logic ...</p>
<p># VULNERABILITY: Spawning a new thread for every single message without limits
    thread = threading.Thread(
        target=copy_current_request_context(ws_generate_data),
        args=(ws, ui_request),
        daemon=True,
    )
    thread.start()
```
### PoC
To reproduce this vulnerability, you only need a running instance of a Mesop application and a basic Python script to flood the WebSocket endpoint.</p>
<p>Prerequisites:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jr7-6hqp-x679"/>
  </entry>
</feed>
