websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1.
References
Configurations
History
No history.
Information
Published : 2026-07-17 20:17
Updated : 2026-08-06 16:17
NVD link : CVE-2026-54463
Mitre link : CVE-2026-54463
CVE.ORG link : CVE-2026-54463
JSON object : View
Products Affected
faye
- websocket-driver
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
