CVE-2026-54463

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:faye:websocket-driver:*:*:*:*:*:ruby:*:*

History

No history.

Information

Published : 2026-07-17 20:17

Updated : 2026-08-06 16:17


NVD link : CVE-2026-54463

Mitre link : CVE-2026-54463

CVE.ORG link : CVE-2026-54463


JSON object : View

Products Affected

faye

  • websocket-driver
CWE
CWE-770

Allocation of Resources Without Limits or Throttling