Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

DoS due to excessively large websocket message in ws

GHSA-6663-c963-2gqg · CVE-2016-10542

Published · Modified

Description

Affected versions of ws do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.

Recommendation

Update to version 1.1.1 or later.
Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.

Ready to move

Start Securing

Free, no credit card | First findings in minutes