Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. mesop
  4. ›
  5. CVE-2026-34824

CVE-2026-34824: Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service

April 3, 2026 (updated April 6, 2026)

An uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework.

References

  • github.com/advisories/GHSA-3jr7-6hqp-x679
  • github.com/mesop-dev/mesop
  • github.com/mesop-dev/mesop/commit/760a2079b5c609038c826d24dfbcf9b0be98d987
  • github.com/mesop-dev/mesop/releases/tag/v1.2.5
  • github.com/mesop-dev/mesop/security/advisories/GHSA-3jr7-6hqp-x679
  • nvd.nist.gov/vuln/detail/CVE-2026-34824

Code Behaviors & Features

Detect and mitigate CVE-2026-34824 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.2.3 before 1.2.5

Fixed versions

  • 1.2.5

Solution

Upgrade to version 1.2.5 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-125: Out-of-bounds Read
  • CWE-400: Uncontrolled Resource Consumption

Source file

pypi/mesop/CVE-2026-34824.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:19:41 +0000.