Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue.
History

Wed, 04 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Textream
Textream textream
CPEs cpe:2.3:a:textream:textream:*:*:*:*:*:*:*:*
Vendors & Products Textream
Textream textream

Wed, 04 Mar 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared F
F textream
Vendors & Products F
F textream

Mon, 02 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
Description Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue.
Title Textream Vulnerable to Uncontrolled Resource Consumption (Denial of Service)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-02T19:22:31.210Z

Reserved: 2026-02-27T15:33:57.289Z

Link: CVE-2026-28412

cve-icon Vulnrichment

Updated: 2026-03-02T19:22:23.285Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-02T16:16:25.930

Modified: 2026-03-04T15:08:31.960

Link: CVE-2026-28412

cve-icon Redhat

No data.