Intel

AIKIDO-2024-10384

laravel/reverb is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 29, 2024

60

Medium Risk

This Affects:

phplaravel/reverb
1.0.0 - 1.0.0
Fixed in 1.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Denial of Service (DoS) when pushing a message with data: "". This causes the server to crash or become unresponsive due to improper handling of empty data payloads. Attackers can exploit this vulnerability by sending crafted requests with empty data, leading to a server outage or degradation of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

laravel/reverb is vulnerable to Denial of Service (DoS) in versions 1.0.0 - 1.0.0.

How to fix this

Upgrade the laravel/reverb library to the patch version.