7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether ws is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.4
CVE-2026-45736
ws: Uninitialized memory disclosure
HIGH 7.5
CVE-2026-48779
ws: Memory exhaustion DoS from tiny fragments and data chunks
HIGH 7.5
CVE-2024-37890
ws affected by a DoS when handling a request with many HTTP headers
HIGH 7.5
GHSA-5v72-xg48-5rpm
Denial of Service in ws
MEDIUM 5.3
CVE-2021-32640
ReDoS in Sec-Websocket-Protocol header
UNKNOWN
CVE-2016-10542
DoS due to excessively large websocket message in ws
UNKNOWN
CVE-2016-10518
Remote Memory Disclosure in ws
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes