CVE-2026-61666
- EPSS 0.34%
- Veröffentlicht 17.08.2026 16:16:33
- Zuletzt bearbeitet 17.08.2026 17:16:39
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote clie...
CVE-2026-54466
- EPSS 0.22%
- Veröffentlicht 17.07.2026 20:53:24
- Zuletzt bearbeitet 06.08.2026 15:52:32
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes w...
CVE-2026-54465
- EPSS 0.34%
- Veröffentlicht 17.07.2026 20:06:06
- Zuletzt bearbeitet 06.08.2026 15:59:01
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can...
CVE-2026-54463
- EPSS 0.34%
- Veröffentlicht 17.07.2026 20:05:17
- Zuletzt bearbeitet 06.08.2026 16:17:59
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bi...