Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-45736

33
FAUCET Score

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

First published: May 15, 2026Last modified: May 15, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 8.20.1CPE matchmatch criteria
cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

4.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.7
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
51.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0075 is in the 27th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: wsFixed in: 8.20.1

Vendor Advisories (2)

npmGHSA-58qx-3vcg-4xpxmedium

ws: Uninitialized memory disclosure

May 18, 2026
microsoft2026-May/CVE-2026-45736Moderate

ws: Uninitialized memory disclosure

May 12, 2026

References

access.redhat.com / errata/RHSA-2026:26638
access.redhat.com / errata/RHSA-2026:26994
access.redhat.com / errata/RHSA-2026:27171
access.redhat.com / errata/RHSA-2026:29197
access.redhat.com / errata/RHSA-2026:33574
access.redhat.com / errata/RHSA-2026:34374
access.redhat.com / errata/RHSA-2026:36754
access.redhat.com / errata/RHSA-2026:36820
access.redhat.com / errata/RHSA-2026:37272
access.redhat.com / errata/RHSA-2026:40768
access.redhat.com / errata/RHSA-2026:40792
access.redhat.com / errata/RHSA-2026:41928
access.redhat.com / errata/RHSA-2026:7655
access.redhat.com / security/cve/CVE-2026-45736
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-45736.json
github.com / websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086
Patch
github.com / websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx
ExploitPatchVendor Advisory