CVE 4.4 MEDIUM

ws: Uninitialized memory disclosure_CVE-2026-45736

4.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Description

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

Basic Information

ID CVE-2026-45736
Source GitHub_M
Published May 15, 2026 at 14:53

Affected Product

Vendor websockets
Product ws
Version >= 8.0.0, < 8.20.1
Affected Versions websockets ws >= 8.0.0, < 8.20.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.