GHSA-6fc8-4gx4-v693

Suggest an improvement
Source
https://github.com/advisories/GHSA-6fc8-4gx4-v693
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-6fc8-4gx4-v693/GHSA-6fc8-4gx4-v693.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6fc8-4gx4-v693
Aliases
Related
Published
2021-05-28T19:19:03Z
Modified
2023-11-08T04:05:55.363871Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
ReDoS in Sec-Websocket-Protocol header
Details

Impact

A specially crafted value of the Sec-Websocket-Protocol header can be used to significantly slow down a ws server.

Proof of concept

for (const length of [1000, 2000, 4000, 8000, 16000, 32000]) {
  const value = 'b' + ' '.repeat(length) + 'x';
  const start = process.hrtime.bigint();

  value.trim().split(/ *, */);

  const end = process.hrtime.bigint();

  console.log('length = %d, time = %f ns', length, end - start);
}

Patches

The vulnerability was fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff) and backported to ws@6.2.2 (https://github.com/websockets/ws/commit/78c676d2a1acefbc05292e9f7ea0a9457704bf1b) and ws@5.2.3 (https://github.com/websockets/ws/commit/76d47c1479002022a3e4357b3c9f0e23a68d4cd2).

Workarounds

In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the --max-http-header-size=size and/or the maxHeaderSize options.

Credits

The vulnerability was responsibly disclosed along with a fix in private by Robert McLaughlin from University of California, Santa Barbara.

Database specific
{
    "github_reviewed_at": "2021-05-28T18:18:04Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-345",
        "CWE-400"
    ],
    "github_reviewed": true,
    "nvd_published_at": "2021-05-25T19:15:00Z"
}
References

Affected packages

npm / ws

Package

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.4.6

npm / ws

Package

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0
Fixed
6.2.2

npm / ws

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.2.3