NRDAX-T0369 - WebSocket Task Spawn Exhaustion
Connection exhaustion (also memory amplification) · RPC and public API · no bound · active · first seen 2026-07-08
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
NullRabbit source-traced H4 slow-read
live exposure
No exposure data. Slashr ↗ has no risk signal mapped to this technique yet — absence of data is not absence of exposure.
instances (1)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| sui | sui_jsonrpsee_h4_ws_task_spawn | lab | NullRabbit Labs | sui_jsonrpsee_h4_ws_task_spawn | - |
related (Connection exhaustion)
NRDAX-T0041 - Cross-Chain Peer Pool Pollution active NRDAX-T0064 - Endpoint Concurrency Cap Exhaustion active NRDAX-T0099 - Half-Open Handshake Slowloris active NRDAX-T0214 - Protocol Message Flood Unbounded Goroutine active NRDAX-T0225 - QUIC Control Frame Flood active NRDAX-T0246 - Rate-Limit Key Confusion active NRDAX-T0261 - RPC Request Flood active NRDAX-T0291 - Subscription Permit Exhaustion active
cite
https://nrdax.com/techniques/NRDAX-T0369
plain
NRDAX Registry. Technique NRDAX-T0369.
bibtex
@misc{nrdax_NRDAX_T0369,
title = {WebSocket Task Spawn Exhaustion (NRDAX-T0369)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0369},
} json (csl)
{
"id": "nrdax-NRDAX-T0369",
"type": "dataset",
"title": "WebSocket Task Spawn Exhaustion (NRDAX-T0369)",
"URL": "https://nrdax.com/techniques/NRDAX-T0369",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0369-websocket-task-spawn-exhaustion)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0369 nrdax cite NRDAX-T0369 --format bibtex