#WebSocket
All CosmicBytez Labs articles tagged #WebSocket, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-82041: Missing Authorization in UTMStack's Incident Command WebSocket Enables Authenticated RCE
Critical CVSS 9.9 missing-authorization flaw in UTMStack lets any authenticated user run OS commands on monitored endpoints; fixed in v11.2.16.
- Security
CVE-2026-95102: Critical Missing Authentication in Monta EV Charging Platform's WebSocket Endpoints
CVSS 9.4: Monta EV charging WebSocket endpoints lack authentication, allowing attackers to impersonate charging stations.
- Security
CVE-2026-62283: Nezha Monitoring WebSocket Terminal Stream Hijacking
CVSS 9.9: Nezha Monitoring fails to bind WebSocket terminal stream IDs to their creator, letting any authenticated user hijack another user's terminal session.
- Security
CVE-2026-53546: Termix WebSocket Host Bypass Grants Cross-User SSH Access
Termix terminal WebSocket accepts attacker-controlled host IDs without ownership checks, enabling cross-user SSH access to any managed server. CVSS 9.6.
- Security
CVE-2026-71319: Critical Nuxt DevTools WebSocket RCE (CVSS 9.6)
A critical unauthenticated RCE vulnerability in Nuxt DevTools exposes a bidirectional RPC channel over the Vite HMR WebSocket, allowing any host on the...
- Security
Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)
A critical authorization bypass in Coolify's terminal WebSocket bootstrap routes allows authenticated users to access server terminals for resources...
- Security
Coolify CVE-2026-34048: Low-Privilege Terminal Escalation via WebSocket (CVSS 9.9)
A critical privilege escalation flaw in Coolify's terminal WebSocket routes lets any low-privileged team member connect to privileged server terminals by...
- Security
CVE-2026-11807: Critical Authorization Bypass in Event-Driven Ansible WebSocket API
A missing authorization flaw (CVSS 9.6) in Red Hat's Event-Driven Ansible allows any authenticated user to forge WebSocket messages and access plaintext...
- News
New RoadK1ll WebSocket Implant Used to Pivot on Breached
Security researchers have identified a newly discovered malicious implant named RoadK1ll that leverages WebSocket connections to silently move from an...
- Security
CVE-2026-22172: OpenClaw Critical Authorization Bypass via WebSocket Scope Elevation
A critical CVSS 9.9 authorization bypass in OpenClaw allows authenticated users to self-declare elevated scopes over WebSocket connections without...