ws

Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js

npm latest 8.21.3 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.21.3

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

7 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

7

ws: Memory exhaustion DoS from tiny fragments and data chunks

Affected range

SEMVER: introduced 1.1.0; fixed 5.2.5SEMVER: introduced 6.0.0; fixed 6.2.4SEMVER: introduced 7.0.0; fixed 7.5.11SEMVER: introduced 8.0.0; fixed 8.21.0

Fixed versions: 5.2.5, 6.2.4, 7.5.11, 8.21.0

ws affected by a DoS when handling a request with many HTTP headers

Affected range

SEMVER: introduced 2.1.0; fixed 5.2.4SEMVER: introduced 6.0.0; fixed 6.2.3SEMVER: introduced 7.0.0; fixed 7.5.10SEMVER: introduced 8.0.0; fixed 8.17.1

Fixed versions: 5.2.4, 6.2.3, 7.5.10, 8.17.1

Denial of Service in ws

Affected range

SEMVER: introduced 0.6.0; fixed 1.1.5SEMVER: introduced 2.0.0; fixed 3.3.1

Fixed versions: 1.1.5, 3.3.1

ReDoS in Sec-Websocket-Protocol header

Affected range

SEMVER: introduced 7.0.0; fixed 7.4.6SEMVER: introduced 6.0.0; fixed 6.2.2SEMVER: introduced 5.0.0; fixed 5.2.3

Fixed versions: 7.4.6, 6.2.2, 5.2.3