Skip to main content

Vendor/product archive

ws_project / ws CVEs

Beta · best-effort

5 CVEs tagged to ws_project / ws0 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-48779

Published Jun 17, 2026

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.…

CVSS 7.5 · High
evidence mentions
26
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-45736

Published May 15, 2026

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedAr…

CVSS 4.4 · Medium
evidence mentions
20
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2016-10542

Published May 31, 2018

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10518

Published May 31, 2018

A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame. The ping functionality by defau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1