PatchSiren

mesop-dev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mesop-dev CVE published 2026-08-25

CVE-2026-77357

The Mesop UI framework, a Python-based UI framework used for building web applications, has a vulnerability in its debug mode. This vulnerability, identified as CVE-2026-77357, allows an unauthenticated attacker to crash the server by exploiting an unbounded loop dependent on a user-supplied counter parameter in the GET /hot-reload endpoint. The issue, fixed in version 1.3.3, can lead to worker exhaustion [truncated]

HIGH Mesop Dev CVE published 2026-04-03

CVE-2026-34824

CVE-2026-34824 is an uncontrolled resource consumption vulnerability in Mesop, a Python-based UI framework. An unauthenticated attacker can cause a Denial of Service (DoS) by sending a rapid succession of WebSocket messages, leading to thread exhaustion and Out of Memory (OOM) errors. This issue has been patched in version 1.2.5. The vulnerability affects Mesop framework versions 1.2.3 to before 1.2.5, an [truncated]