AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-21035

HIGH · CVSS 7.5 EPSS 2.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-02-28 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-21035
Severity
HIGH
CVSS
7.5
EPSS
2.34%

Original Filing — NVD Description

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).