websockets
Library for building WebSocket servers and clients in Python
Activity
- Latest release
- 1d ago
- Total releases
- 51
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Stars
- 5.7k
Details
- License
- BSD-3-Clause
- First release
- Nov 14, 2013
| Version | Released | |
|---|---|---|
17.0.1
patch
| ||
17.0
major
| ||
16.1.1
patch
| ||
16.1
minor
| ||
16.0
major
| ||
15.0.1
patch
| ||
15.0
major
| ||
14.2
minor
| ||
14.1
minor
| ||
14.0
major
| ||
13.1
minor
| ||
13.0.1
patch
| ||
13.0
major
| ||
12.0
major
| ||
11.0.3
patch
| ||
11.0.2
patch
| ||
11.0.1
patch
| ||
11.0
major
| ||
10.4
minor
| ||
10.3
minor
| ||
10.2
minor
| ||
10.1
minor
| ||
10.0
major
| ||
9.1
minor
| ||
9.0.2
patch
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
9.0.1
patch
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
9.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
8.1
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
8.0.2
patch
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
8.0.1
patch
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
8.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
7.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
6.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
5.0.1
patch
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
5.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
4.0.1
patch
2 CVEs
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev
CVE-2018-1000518
GHSA-6g87-ff9q-v847
PYSEC-2018-79
Sep 17, 2018
websockets is vulnerable to denial of service by memory exhaustion
High
Network
Low
None
None
The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appears to be exploitable via sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in version 5.0 Affected versions
4.0
4.0.1
Fixed in
5.0
References Updated Nov 19, 2024 · Source: OSV.dev | ||
4.0
major
2 CVEs
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev
CVE-2018-1000518
GHSA-6g87-ff9q-v847
PYSEC-2018-79
Sep 17, 2018
websockets is vulnerable to denial of service by memory exhaustion
High
Network
Low
None
None
The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appears to be exploitable via sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in version 5.0 Affected versions
4.0
4.0.1
Fixed in
5.0
References Updated Nov 19, 2024 · Source: OSV.dev | ||
3.4
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
3.3
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
3.2
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
3.1
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
3.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.7
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.6
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.5
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.4
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.3
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.2
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.1
minor
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev | ||
2.0
major
1 CVE
CVE-2021-33880
GHSA-8ch4-58qp-g3mp
PYSEC-2021-95
Jun 11, 2021
Observable Timing Discrepancy in aaugustin websockets library
High
Network
Low
None
None
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. Affected versions
0.1
1.0
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
3.0
3.1
+ 16 more Show less
3.2
3.3
3.4
4.0
4.0.1
5.0
5.0.1
6.0
7.0
8.0
8.0.1
8.0.2
8.1
9.0
9.0.1
9.0.2
Fixed in
9.1
References
Updated Nov 19, 2024 · Source: OSV.dev |