# CVE-2026-62963

## Summary

- **CVE ID:** CVE-2026-62963
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-409
- **Published:** Jul 16, 2026
- **Last Modified:** Jul 17, 2026

## Description

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in internal/websocket/conn.go advanceFrame, but ReadMessage used io.ReadAll after decompression without an output cap, allowing unauthenticated requests to /connection/uni_websocket to trigger large memory and CPU consumption. This issue is fixed in version 6.8.4.

## Affected Products

- centrifugal — centrifugo (< 6.8.4)

## References

- [CNA](https://github.com/centrifugal/centrifugo/security/advisories/GHSA-q6mr-3g59-5m8x)
- [CNA](https://github.com/centrifugal/centrifugo/pull/1162)
- [CNA](https://github.com/centrifugal/centrifugo/commit/46d40e4ac3a5446c9745f8b219197166ae12a6e5)
- [CNA](https://github.com/centrifugal/centrifugo/releases/tag/v6.8.4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.52%
- **EPSS Percentile:** 42.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._