{"id":"CVE-2026-10099","summary":"XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py","details":"XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending unmasked WebSocket frames. The server unconditionally reads 4 bytes as a masking key regardless of whether the MASK bit is set in the frame header, causing the first 4 bytes of payload to be consumed as a mask key and the remaining payload to be incorrectly XOR-decoded, resulting in data corruption alongside missing RSV bit, opcode, and FIN fragmentation validations.","modified":"2026-08-12T03:51:22.729034284Z","published":"2026-05-29T15:58:24.062Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-1286"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10099.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"43aec6f"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10099.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10099"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/xx-net-websocket-frame-parsing-data-corruption-via-simple-http-server-py"},{"type":"REPORT","url":"https://github.com/XX-net/XX-Net/issues/14169"},{"type":"REPORT","url":"https://github.com/XX-net/XX-Net/pull/14170"},{"type":"FIX","url":"https://github.com/XX-net/XX-Net/commit/a68b972a84ed6e52df9f30237cf47493b9231b53"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xx-net/xx-net","events":[{"introduced":"0"},{"fixed":"a68b972a84ed6e52df9f30237cf47493b9231b53"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.16.6"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["5.16.6","5.16.5","5.10.7","5.9.10","5.9.9","5.9.0","5.8.6","5.8.5","5.8.4","5.8.3","5.8.1","5.7.7","5.7.5","5.7.4","5.7.3","5.6.2","5.6.1","5.6.0","5.5.13","5.5.10","5.5.9","5.5.8","5.5.6","5.5.5","5.5.4","5.5.2","5.5.1","5.5.0","5.4.5","5.4.2","5.4.0","5.3.2","5.3.0","5.2.0","5.1.1","5.1.0","5.0.8","5.0.7","5.0.6","5.0.5","5.0.4","4.13.7","4.13.6","4.14.5","4.14.4","4.13.3","4.13.2","4.13.1","4.12.5","4.12.2","4.12.1","4.12.0","4.11.5","4.11.4","4.11.3","4.11.2","4.10.0","4.9.9","4.9.8","4.9.7","4.9.6","4.9.5","4.9.4","4.9.3","4.9.2","4.9.1","4.9.0","4.8.1","4.8.0","4.7.11","4.7.10","4.7.9","4.7.8","4.7.7","4.7.6","4.7.5","4.7.4","4.7.3","4.7.2","4.7.1","4.7.0","4.6.8","4.6.7","4.6.6","4.6.5","4.6.4","4.6.3","4.6.2","4.6.1","4.6.0","4.5.6","4.5.4","4.5.3","4.5.2","4.5.1","4.5.0","4.4.3","4.4.2","4.4.1","4.4.0","4.3.0","4.2.0","4.1.2","4.1.1","4.1.0","4.0.5","4.0.4","4.0.3","4.0.2","4.0.1","4.0.0","3.16.0","3.15.10","3.15.9","3.15.8","3.15.7","3.15.6","3.15.5","3.15.4","3.15.3","3.15.2","3.15.1","3.15.0","3.14.2","3.14.1","3.14.0","3.13.4","3.13.1","3.13.0","3.12.11","3.12.10","3.12.9","3.12.8","3.12.7","3.12.6","3.12.5","3.12.4","3.12.2","3.12.1","3.12.0","3.11.15","3.11.14","3.11.13","3.11.11","3.11.10","3.11.9","3.11.8","3.11.7","3.11.6","3.11.5","3.11.4","3.11.3","3.11.2","3.11.1","3.11.0","3.10.8","3.10.7","3.10.6","3.10.5","3.10.4","3.10.3","3.10.2","3.10.1","3.10.0","3.9.6","3.9.5","3.9.4","3.9.3","3.9.2","3.9.1","3.9.0","3.8.6","3.8.5","3.8.4","3.8.3","3.8.2","3.8.1","3.8.0","3.7.17","3.7.16","3.7.15","3.7.14","3.7.13","3.7.12","3.7.11","3.7.10","3.7.9","3.7.8","3.7.7","3.7.6","3.7.5","3.7.4","3.7.3","3.7.2","3.7.1","3.7.0","3.6.16","3.6.15","3.6.14","3.6.13","3.6.12","3.6.11","3.6.10","3.6.9","3.6.8","3.6.7","3.6.6","3.6.5","3.6.4","3.6.3","3.6.2","3.6.1","3.6.0","3.5.6","3.5.5","3.5.4","3.5.3","3.5.2","3.5.1","3.5.0","3.4.2","3.4.1","3.4.0","3.3.6","3.3.5","3.3.4","3.3.3","3.3.2","3.3.1","3.2.7","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.19","3.1.18","3.1.17","3.1.16","3.1.15","3.1.14","3.1.13","3.1.12","3.1.11","3.1.10","3.1.9","3.1.8","3.1.7","3.1.6","3.1.5","3.1.4","3.1.3","3.1.2","3.1.1","3.1.0","3.0.4","3.0.3","3.0.2","3.0.1","3.0.0","2.9.6","2.9.4","2.9.3","2.9.2","2.9.1","2.9.0","2.8.10","2.8.9","2.8.8","2.8.7","2.8.6","2.8.5","2.8.4","2.8.3","2.8.2","2.8.1","2.8.0","2.7.3","2.5.5","2.7.2","2.7.1","2.7.0","2.6.2","2.6.1","2.6.0","2.5.4","2.5.3","2.5.2","2.5.1","2.5.0","2.4.0","2.3.0","2.1.2","2.2.0","2.1.1","2.1.0","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.16.4","1.16.3","1.16.2","1.16.1","1.16.0","1.15.2","1.15.1","1.15.0","1.14.11","1.14.10","1.14.9","1.14.8","1.14.6","1.14.5","1.14.4","1.14.3","1.14.2","1.14.1","1.14.0","1.13.6","1.13.5","1.13.4","1.13.3","1.13.1","1.13.0","1.12.5","1.12.4","1.12.3","1.12.2","1.12.1","1.12.0","1.10.1","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0","1.8.12","1.8.11","1.8.10","1.8.9","1.8.8","1.8.7","1.8.6","1.8.5","1.8.4","1.8.3","1.8.2","1.8.1","1.8.0","1.7.2","1.7.1","1.7.0","1.6.0","1.5.5","1.5.3","1.5.2","1.5.1","1.5.0","1.4.1","1.4.0","1.3.6","1.3.5","1.3.4","1.3.3","1.3.2","1.3.1","1.3.0","1.2.1","1.2.0","1.1.0","1.0.9","1.0.7","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10099.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}