The Websocket Extensions Project maintains a narrowly scoped library that provides extension mechanisms for WebSocket protocol implementations, embedded across a diverse set of applications and frameworks that rely on real-time bidirectional communication. While the product's vulnerability footprint is compact, its role in protocol handling across the supply chain warrants monitoring; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Websocket Extensions Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7663HIGH websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing | Jun 2, 2020 | 7.5 | 27 | NO | NO |
CVE-2020-7662HIGH websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing | Jun 2, 2020 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Websocket Extensions Project.
Media articles that mention a CVE ID that affects a product developed by Websocket Extensions Project — matched by CVE ID, not by vendor name.