fastify/websocket vulnerable to uncaught exception via crash on malformed packet
- Severity:
- High
Description
Any application using @fastify/websocket could crash if a specific, malformed packet is sent.
All versions of fastify-websocket are also impacted. That module is deprecated, so it will not be patched.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.3.0
References
Related Issues
- JOSE vulnerable to resource exhaustion via specifically crafted JWE - CVE-2022-36083
- React Editable Json Tree vulnerable to arbitrary code execution via function parsing - CVE-2022-36010
- JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-esm-runtime - CVE-2022-36083
- JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-cjs-runtime - CVE-2022-36083
You might also like:
- Tags:
- npm
- fastify-websocket
Anything's wrong? Let us know Last updated on March 29, 2023


