Vulnerabilities/

Denial of Service in ws

Severity:
High

Description

Affected versions of ws can crash when a specially crafted Sec-WebSocket-Extensions header containing Object.prototype property names as extension or parameter names is sent.

Recommendation

Update the ws package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ws
Anything's wrong? Let us know Last updated on March 23, 2023

This issue is available in SmartScanner Professional

See Pricing