← voltar
CVE-2025-43855

tRPC 11 WebSocket DoS Vulnerability

CVSS 8.7 HIGHEPSS 0.3%CWE-248
tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server. Any tRPC 11 server with WebSocket enabled with a createContext method set is vulnerable. This issue has been patched in version 11.1.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Produtos afetados
trpc · trpc

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →