CVE-2023-43669: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).

Affected products

  • Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
  • Snapview Tungstenite: up to and including 0.20.0

Published 2023-09-21. Last modified 2026-06-17.