ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the…
Medium CVSS 4.4
Summary
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086 Patch
- https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx Exploit
- https://access.redhat.com/errata/RHSA-2026:26638
- https://access.redhat.com/errata/RHSA-2026:26994
- https://access.redhat.com/errata/RHSA-2026:27171
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:33574
- https://access.redhat.com/errata/RHSA-2026:34374
- https://access.redhat.com/errata/RHSA-2026:36754
- https://access.redhat.com/errata/RHSA-2026:36820
- https://access.redhat.com/errata/RHSA-2026:37272
- https://access.redhat.com/errata/RHSA-2026:7655
- https://access.redhat.com/security/cve/CVE-2026-45736
- https://bugzilla.redhat.com/show_bug.cgi?id=2477914
- https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx Exploit
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45736.json
Timeline
- nvd_ingest NVD