ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
References
Configurations
History
No history.
Information
Published : 2026-05-15 15:16
Updated : 2026-09-11 13:18
NVD link : CVE-2026-45736
Mitre link : CVE-2026-45736
CVE.ORG link : CVE-2026-45736
JSON object : View
Products Affected
ws_project
- ws
