136 wires and counting

$ follow OpenAI

Keep up with OpenAI in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-05-03
stories 2

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

CODEX WEBSOCKET TIMEOUT BUG LEAVES STALLED REQUESTS HANGING

By RepoJournal · Filed · About OpenAI · Composed from the cited sources · methodology

A write-side timeout vulnerability in Codex websocket handling lets client requests sit indefinitely when the socket pump stalls, even after the server has already disconnected.

Codex has a timing gap in its websocket implementation that creates asymmetric timeouts [1]. The connection itself is properly bounded by `websocket_connect_timeout_ms`, but once established, the first request send reuses only the receive-side idle timeout—leaving the write path unprotected if the socket pump stalls. This means a client calling `ws_stream.send(...)` can hang indefinitely while the server logs the session as already dead [1]. The fix adds a send-side timeout boundary to match the receive path, ensuring both directions of communication respect the same idle window. This is a quiet but real reliability issue for any service using Codex over websockets under network stress.

Quick answers

What shipped in OpenAI on May 3, 2026?
A write-side timeout vulnerability in Codex websocket handling lets client requests sit indefinitely when the socket pump stalls, even after the server has already disconnected. In total, 1 commits and 1 pull requests landed.
Who contributed to OpenAI on May 3, 2026?
1 developer shipped this update, including pakrym-oai.
What were the notable OpenAI updates?
Bound websocket request sends with idle timeout.