CVE-2026-45736
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
Fraqueza
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
Produtos afetados
- ws_project ws
Referências
- https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086
- https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx
- https://access.redhat.com/errata/RHSA-2026:26638
- https://access.redhat.com/errata/RHSA-2026:26994
- https://access.redhat.com/errata/RHSA-2026:27171
- https://access.redhat.com/errata/RHSA-2026:29197
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.