CVE-2025-43855 - CVE House
Back to Database
Status published High CVE-2025-43855

tRPC 11 WebSocket DoS Vulnerability

Vulnerability Description

tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server. Any tRPC 11 server with WebSocket enabled with a createContext method set is vulnerable. This issue has been patched in version 11.1.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-43855

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Luke Childs <mail@lu.ke>

Affected Vendor

Affected Software

trpc
Vulnerable Versions:
>= 11.0.0, < 11.1.1

Timeline

Official Publish: April 24th, 2025
Last Modified: May 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)