websocket-driver is vulnerable to Denial of Service (DoS)
63
Medium Risk
The WebSocket driver enforces maximum message size against compressed frame headers before extension processing completes. When permessage-deflate is enabled, a peer can send compressed frames whose decompressed payload exceeds the configured limit. This lets attackers bypass intended size caps and drive higher memory use than applications expect. The fix checks message size after incoming extensions process the payload and fails oversized messages.
You are affected if you are using a version that falls within the vulnerable range and use the permessage-deflate extension.
websocket-driver is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.8.0.
Upgrade the websocket-driver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant