Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js
86%
Total Score
79
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-45736 ws is vulnerable to Use of Uninitialized Resource in versions 8.0.0 - 8.20.1. | 8.0.0 - 8.20.1 | Medium |
CVE-2024-37890 ws is vulnerable to NULL Pointer Dereference in versions 2.1.0 - 5.2.4, 6.0.0 - 6.2.3, 7.0.0 - 7.5.10 and 8.0.0 - 8.17.1. | 2.1.0 - 5.2.46.0.0 - 6.2.37.0.0 - 7.5.10 +1 more | High |
CVE-2021-32640 ws is vulnerable to Insufficient Verification of Data Authenticity in versions 7.0.0 - 7.4.6, 6.0.0 - 6.2.2 and 5.0.0 - 5.2.3. | 5.0.0 - 5.2.36.0.0 - 6.2.27.0.0 - 7.4.6 | Medium |
CVE-2016-10518 ws is vulnerable to Insertion of Sensitive Information Into Sent Data in versions 0.0.0 - 1.0.1. | 0.0.0 - 1.0.1 | High |
CVE-2016-10542 ws is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 1.1.1. | 0.0.0 - 1.1.1 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant