Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-48779

36
FAUCET Score

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

First published: Jun 16, 2026Last modified: Jun 16, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.0, < 5.2.5CPE matchmatch criteria
cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*
>= 6.0.0, < 6.2.4CPE matchmatch criteria
cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*
>= 7.0.0, < 7.5.11CPE matchmatch criteria
cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*
>= 8.0.0, < 8.21.0CPE matchmatch criteria
cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.78%
Probability of exploitation in next 30 days
EPSS Percentile
52.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0078 is in the 28th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: wsFixed in: 5.2.5
npmpatch availablevia ghsa
Product: wsFixed in: 6.2.4
npmpatch availablevia ghsa
Product: wsFixed in: 7.5.11
npmpatch availablevia ghsa
Product: wsFixed in: 8.21.0

Vendor Advisories (2)

npmGHSA-96hv-2xvq-fx4phigh

ws: Memory exhaustion DoS from tiny fragments and data chunks

Jun 15, 2026
microsoft2026-Jun/CVE-2026-48779Important

ws: Memory exhaustion DoS from tiny fragments and data chunks

Jun 9, 2026

References

access.redhat.com / errata/RHSA-2026:29197
access.redhat.com / errata/RHSA-2026:33155
access.redhat.com / errata/RHSA-2026:33160
access.redhat.com / errata/RHSA-2026:33163
access.redhat.com / errata/RHSA-2026:33173
access.redhat.com / errata/RHSA-2026:33183
access.redhat.com / errata/RHSA-2026:33574
access.redhat.com / errata/RHSA-2026:34342
access.redhat.com / errata/RHSA-2026:36754
access.redhat.com / errata/RHSA-2026:36820
access.redhat.com / errata/RHSA-2026:37272
access.redhat.com / errata/RHSA-2026:40984
access.redhat.com / errata/RHSA-2026:41928
access.redhat.com / errata/RHSA-2026:41941
access.redhat.com / errata/RHSA-2026:41944
access.redhat.com / security/cve/CVE-2026-48779
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-48779.json
github.com / websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7
Patch
github.com / websockets/ws/commit/b5372ac67bb97a773727b8e9f5035a8123556d53
Patch
github.com / websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94
Patch
github.com / websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8
Patch
github.com / websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p
ExploitMitigationPatchVendor Advisory