Lucene search

K
nodejsFedor IndutnyNODEJS:120
HistoryJun 24, 2016 - 12:34 a.m.

DoS due to excessively large websocket message

2016-06-2400:34:25
Fedor Indutny
www.npmjs.com
54

0.001 Low

EPSS

Percentile

43.0%

Overview

Affected versions of ws do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.

Recommendation

Update to version 1.1.1 or later.
Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.

References

CPENameOperatorVersion
wsle1.1.0

0.001 Low

EPSS

Percentile

43.0%