Denial of Service in ws
High severity
GitHub Reviewed
Published
Jun 4, 2019
to the GitHub Advisory Database
•
Updated Mar 23, 2023
Description
Reviewed
Jun 4, 2019
Published to the GitHub Advisory Database
Jun 4, 2019
Last updated
Mar 23, 2023
Affected versions of
ws
can crash when a specially craftedSec-WebSocket-Extensions
header containingObject.prototype
property names as extension or parameter names is sent.Proof of concept
Recommendation
Update to version 3.3.1 or later.
References