๐Ÿ” CVE Alert

CVE-2026-55768

UNKNOWN 0.0

GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.

CWE CWE-789 CWE-681
Vendor allinurl
Product goaccess
Published Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for allinurl goaccess

Be the first to know when new unknown vulnerabilities affecting allinurl goaccess are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

allinurl / goaccess
< 1.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46 github.com: https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5