Lucene search

K
osvGoogleOSV:GHSA-6663-C963-2GQG
HistoryFeb 18, 2019 - 11:58 p.m.

DoS due to excessively large websocket message in ws

2019-02-1823:58:35
Google
osv.dev
18

0.001 Low

EPSS

Percentile

43.0%

Affected versions of ws do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.

Recommendation

Update to version 1.1.1 or later.
Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.

CPENameOperatorVersion
wslt1.1.1

0.001 Low

EPSS

Percentile

43.0%