{"id":"CVE-2023-43669","details":"The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).","aliases":["GHSA-9mcr-873m-xcxp","RUSTSEC-2023-0065"],"modified":"2026-08-12T03:51:46.573780009Z","published":"2023-09-21T00:00:00Z","related":["CGA-cxr6-whqp-4grc"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43669.json"},"references":[{"type":"WEB","url":"https://crates.io/crates/tungstenite/versions"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/407.html"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2023-43669"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43669.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9mcr-873m-xcxp"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R77EUWPZVP5WSMNXUXUDNHR7G7OI5NGM/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THK6G6CD4VW6RCROWUV2C4HSINKK3XAK/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT7SF6CQ5VHAGFLWNXY64NFSW4WIWE7D/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43669"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2240110"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1215563"},{"type":"REPORT","url":"https://github.com/snapview/tungstenite-rs/issues/376"},{"type":"FIX","url":"https://github.com/github/advisory-database/pull/2752"},{"type":"FIX","url":"https://github.com/snapview/tungstenite-rs/commit/8b3ecd3cc0008145ab4bc8d0657c39d09db8c7e2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/snapview/tungstenite-rs","events":[{"introduced":"0"},{"fixed":"8b3ecd3cc0008145ab4bc8d0657c39d09db8c7e2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.20.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:snapview:tungstenite:*:*:*:*:*:rust:*:*"}}],"versions":["v0.20.1","v0.20.0","v0.19.0","v0.18.0","v0.17.3","v0.17.2","v0.17.1","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.1","v0.11.0","v0.10.1","v0.10.0","v0.9.2","v0.9.1","v0.9.0","v0.8.1","v0.8.0","v0.7.0","v0.6.1","v0.6.0","v0.5.3","v0.5.2","v0.5.1","v0.5.0","v0.4.0","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43669.json"}}],"schema_version":"1.9.0"}