Advisories for Pypi/Websockets package

2021

Observable Timing Discrepancy

The aaugustin websockets library for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled. An attacker may be able to guess a password via a timing attack.

2018