云虫漏洞库

CVE-2026-48779 - ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default docu - 漏洞详情

漏洞编号:CVE-2026-48779

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-48779

CNNVD 编号:-

厂商/产品:ws_project / ws

影响范围:cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*

CWE:CWE-400

发布/更新时间:2026-06-17 / 2026-08-28

漏洞描述

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

相关链接

相关漏洞

« 返回首页