Vulnerabilities/

ReDoS in Sec-Websocket-Protocol header

Severity:
Medium

Description

A specially crafted value of the Sec-Websocket-Protocol header can be used to significantly slow down a ws server.

Recommendation

Update the ws package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ws
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing