Junglewise Threat Intelligence

CVE-2023-26151: PYSEC-2023-190 - Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet an

CVE-2023-26151 · Severity: low · CVSS 3.1 · Published 2023-10-03

Technologies: asyncua (PyPI). Vendors: PyPI.

Executive brief

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

Affected products

  • PyPI asyncua

Related threats