The gateway accepted unbounded concurrent unauthenticated WebSocket upgrades before allocating them to an authenticated session budget.
An unauthenticated network attacker could consume socket and worker capacity and disrupt WebSocket availability for legitimate clients.
src/gateway/server-http.ts, src/gateway/server/preauth-connection-budget.ts
<= 2026.3.24>= 2026.3.282026.3.28 contains the fix.Fixed by commit cb5f7e201f (gateway: cap concurrent pre-auth websocket upgrades).
Discovered by:Topsec AlphaLab (wang dong)
{
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-31T23:54:00Z",
"nvd_published_at": null,
"severity": "MODERATE"
}