UNKNOWN npm
DoS due to excessively large websocket message in ws
GHSA-6663-c963-2gqg · CVE-2016-10542
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Affected versions of ws do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.
Recommendation
Update to version 1.1.1 or later.
Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.
Ready to move
Start Securing
Free, no credit card | First findings in minutes