ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the Sec-Websocket-Protocol header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the --max-http-header-size=size and/or the maxHeaderSize options.
{
"cpe": "cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*",
"extracted_events": [
{
"introduced": "5.0.0"
},
{
"fixed": "6.2.2"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.4.6"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}