Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/f/textream/commit/3524fa96f98ba17025b48ce9e19d49d859fc2ec1 | Patch |
| https://github.com/f/textream/security/advisories/GHSA-qr5p-7x47-qxh9 | Exploit Vendor Advisory |
Configurations
History
10 Mar 2026, 18:23
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:fka:textream:*:*:*:*:*:*:*:* | |
| First Time |
Fka
Fka textream |
04 Mar 2026, 15:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Textream
Textream textream |
|
| References | () https://github.com/f/textream/commit/3524fa96f98ba17025b48ce9e19d49d859fc2ec1 - Patch | |
| References | () https://github.com/f/textream/security/advisories/GHSA-qr5p-7x47-qxh9 - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:textream:textream:*:*:*:*:*:*:*:* |
02 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-02 16:16
Updated : 2026-03-10 18:23
NVD link : CVE-2026-28412
Mitre link : CVE-2026-28412
CVE.ORG link : CVE-2026-28412
JSON object : View
Products Affected
fka
- textream
CWE
CWE-400
Uncontrolled Resource Consumption
