Ws Project maintains a niche WebSocket implementation whose vulnerability profile centers on resource handling and input-parsing defects such as uncontrolled resource consumption, improper input validation, buffer-boundary violations, and sensitive-data leakage. These weakness classes reflect the protocol-parsing demands inherent to real-time communication libraries that process untrusted network data. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ws Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48779HIGH ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0 | Jun 16, 2026 | 7.5 | 36 | NO | NO |
CVE-2016-10542HIGH ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket paylo | May 31, 2018 | 7.5 | 34 | NO | YES |
CVE-2026-45736HIGH ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArr | May 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2016-10518HIGH A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame. The ping functionality by defaul | May 31, 2018 | 7.5 | 22 | NO | NO |
CVE-2021-32640MEDIUM ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws s | May 25, 2021 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ws Project.
Media articles that mention a CVE ID that affects a product developed by Ws Project — matched by CVE ID, not by vendor name.