Skip to content

Security Vulnerability: CVE-2024-37890- Security Level: HIGH  #165

Open
@essjayhch

Description

@essjayhch

Reported Security Vulnerability with dependency package "ws"
https://www.mend.io/vulnerability-database/CVE-2024-37890

This impacts numerous downstream packages that source this package for websocket behaviours.

A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e55e510) and backported to [email protected] (22c2876), [email protected] (eeb76d3), and [email protected] (4abd8f6)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions