CVE-2026-48779CWE-1050CWE-400CWE-770denial-of-service

CVE-2026-48779

High · published June 17, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
54.6
In the wild
Unconfirmed
What it is

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00812 · 54.6th percentile
Weaknesses
CWE-1050 · Excessive Platform Resource Consumption within a Loop; CWE-400 · Uncontrolled Resource Consumption; CWE-770 · Allocation of Resources Without Limits or Throttling
Published
2026-06-17T17:20Z
Affected products (4)
ProductVersionsFixed in
ws_project/ws≥ 1.1.0, < 5.2.55.2.5
ws_project/ws≥ 6.0.0, < 6.2.46.2.4
ws_project/ws≥ 7.0.0, < 7.5.117.5.11
ws_project/ws≥ 8.0.0, < 8.21.08.21.0
References (30)
https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7 · [email protected]https://github.com/websockets/ws/commit/b5372ac67bb97a773727b8e9f5035a8123556d53 · [email protected]https://github.com/websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94 · [email protected]https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8 · [email protected]https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p · [email protected]https://access.redhat.com/errata/RHSA-2026:29197 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33155 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33160 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33163 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33173 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33183 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33574 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:34342 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:36754 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:36820 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:37272 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:40984 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:41928 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:41941 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:41944 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:48151 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:56366 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:56431 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:57013 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:57590 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:60520 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/security/cve/CVE-2026-48779 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://bugzilla.redhat.com/show_bug.cgi?id=2489661 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p · 134c704f-9b21-4f2e-91b3-4a467353bcc0https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48779.json · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
EPSS history
Timeline
  • 16 JUN 21:26Z
    ws: Memory exhaustion DoS from tiny fragments and data chunks
    cvelistv5