Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js
94%
Total Score
100
100
91
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-138234 ws is vulnerable to Denial of Service (DoS) in versions 5.2.5 - 5.2.5, 6.2.4 - 6.2.4, 7.5.11 - 7.5.11 and 8.21.0 - 8.21.0. | 5.2.5 - 5.2.56.2.4 - 6.2.47.5.11 - 7.5.11 +1 more | High |
CVE-2026-48779 ws is vulnerable to Uncontrolled Resource Consumption in versions 1.1.0 - 5.2.5, 6.0.0 - 6.2.4, 7.0.0 - 7.5.11 and 8.0.0 - 8.21.0. | 1.1.0 - 5.2.56.0.0 - 6.2.47.0.0 - 7.5.11 +1 more | High |
CVE-2026-45736 ws is vulnerable to Use of Uninitialized Resource in versions 8.0.0 - 8.20.1. | 8.0.0 - 8.20.1 | Medium |
CVE-2024-37890 ws is vulnerable to NULL Pointer Dereference in versions 2.1.0 - 5.2.4, 6.0.0 - 6.2.3, 7.0.0 - 7.5.10 and 8.0.0 - 8.17.1. | 2.1.0 - 5.2.46.0.0 - 6.2.37.0.0 - 7.5.10 +1 more | High |
CVE-2021-32640 ws is vulnerable to Insufficient Verification of Data Authenticity in versions 7.0.0 - 7.4.6, 6.0.0 - 6.2.2 and 5.0.0 - 5.2.3. | 5.0.0 - 5.2.36.0.0 - 6.2.27.0.0 - 7.4.6 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant