WS Project / WS
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48779 | ws: Memory exhaustion DoS from tiny fragments and data chunks | HIGH | 7.5 | Jun 16, 2026 |
| CVE-2026-45736 | ws: Uninitialized memory disclosure | HIGH | 7.5 | May 15, 2026 |
| CVE-2021-32640 | ReDoS in Sec-Websocket-Protocol header | MEDIUM | 5.3 | May 25, 2021 |
| CVE-2016-10542 | ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly… | HIGH | 7.5 | May 31, 2018 |
| CVE-2016-10518 | A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame. The ping fu… | HIGH | 7.5 | May 31, 2018 |
Showing 1 to 5 of 5 CVEs