CVE-2026-54465
NONE—CVSS v3
—CVSS v2
0.45%
EPSS (exploit probability)
CWE-770CWE
Description
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1.
Affected routers (0)
No routers currently mapped to this CVE in our database.