websocket-driver
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting websocket-driverpage 1 of 1
- CVE-2026-54466CRITICALCVSS 9.2EG 9.2✓ Fixed in 0.7.52026-07-15
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence…
- CVE-2026-54490MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.7.52026-07-15
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger than the config…
Check whether websocket-driver is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for websocket-driver CVEs against the assets you own.
Start Free Scan →