Description
Any application using @fastify/websocket could crash if a specific, malformed packet is sent.
All versions of fastify-websocket are also impacted. That module is deprecated, so it will not be patched.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.3.0
References
Could your website be exposed too?
SmartScanner can check your website for fastify/websocket vulnerable to uncaught exception via crash on malformed packet and gives you actionable findings to investigate.
Start a free scanRelated Issues
- JOSE vulnerable to resource exhaustion via specifically crafted JWE - CVE-2022-36083
- React Editable Json Tree vulnerable to arbitrary code execution via function parsing - CVE-2022-36010
- JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-esm-runtime - CVE-2022-36083
- JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-cjs-runtime - CVE-2022-36083


