Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue. | |
| Title | Textream Vulnerable to Uncontrolled Resource Consumption (Denial of Service) | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-02T15:46:56.128Z
Updated: 2026-03-02T19:22:31.210Z
Reserved: 2026-02-27T15:33:57.289Z
Link: CVE-2026-28412
No data.
Status : Received
Published: 2026-03-02T16:16:25.930
Modified: 2026-03-02T16:16:25.930
Link: CVE-2026-28412
No data.