CVE Explorer
CVE-2026-28412
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"textream","vendor":"f","versions":[{"status":"affected","version":"< 1.5.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e326ebd5f978a92339ae9b4d9f0c826b65e7e9afe65ebde0edb9a6c88d465899 · sha256:987755ddb80e6d43… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e326ebd5f978a92339ae9b4d9f0c826b65e7e9afe65ebde0edb9a6c88d465899 · sha256:987755ddb80e6d43… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e326ebd5f978a92339ae9b4d9f0c826b65e7e9afe65ebde0edb9a6c88d465899 · sha256:987755ddb80e6d43… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/f/textream/commit/3524fa96f98ba17025b48ce9e19d49d859fc2ec1","tags":["x_refsource_MISC"],"url":"https://github.com/f/textream/commit/3524fa96f98ba17025b48ce9e19d49d859fc2ec1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e326ebd5f978a92339ae9b4d9f0c826b65e7e9afe65ebde0edb9a6c88d465899 · sha256:987755ddb80e6d43… · /containers/cna/references/1
{"name":"https://github.com/f/textream/security/advisories/GHSA-qr5p-7x47-qxh9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/f/textream/security/advisories/GHSA-qr5p-7x47-qxh9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e326ebd5f978a92339ae9b4d9f0c826b65e7e9afe65ebde0edb9a6c88d465899 · sha256:987755ddb80e6d43… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.