Affected versions of ws
do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.
Update to version 1.1.1 or later.
Alternatively, set the maxpayload
option for the ws
server to a value smaller than 256MB.
{ "github_reviewed_at": "2020-06-16T21:18:11Z", "severity": "HIGH", "cwe_ids": [ "CWE-400" ], "github_reviewed": true, "nvd_published_at": null }