CVE-2026-50176Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-25: 2Technical Details · 2026-06-25: 206-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50176 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to co… https://www.cve.org/CVERecord?id=CVE-2026-50176 ----- Traducción: CVE-2026-50176 La … http://infoflow.cloud`

    Post summary

    CVE-2026-50176 is a newly disclosed authentication rate‑limiting flaw in the WebSocket API, with no evidence of PoC, exploit, or active exploitation.

    0000030
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50176 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to co… https://www.cve.org/CVERecord?id=CVE-2026-50176

    Post summary

    The CVE-2026-50176 report identifies a missing rate‑limiting feature on WebSocket authentication, highlighting a potential for brute‑force or denial‑of‑service attacks, but provides no PoC, exploit, active exploitation claims, or patch information.

    00000695
    57.7K followersView on X

Explore more