websocket-driver
RubyGems3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting websocket-driverpage 1 of 1
- CVE-2026-54463MEDIUMCVSS 6.9EG 6.9✓ Fixed in 0.8.12026-07-15
vulnerable: 0.1.0 ... 0.8.0 (32 versions)
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with …
- CVE-2026-54464MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.8.12026-07-15
vulnerable: 0.1.0 ... 0.8.0 (32 versions)
### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size. This is because this limit is chec…
- CVE-2026-54465MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.8.12026-07-15
vulnerable: 0.1.0 ... 0.8.0 (32 versions)
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client,…
Check whether websocket-driver is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for websocket-driver CVEs against the assets you own.
Start Free Scan →