Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09331

Опубликовано: 12 мая 2026
Источник: fstec
CVSS3: 4.4
CVSS2: 4.6
EPSS Низкий

Описание

Уязвимость библиотеки Node.js WebSocket связана с использованием неинициализированного ресурса. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Red Hat Inc.
ООО «РусБИТех-Астра»
NPM, Inc.
АО «СберТех»

Наименование ПО

Red Hat Enterprise Linux
OpenShift Container Platform
Red Hat Quay
Red Hat AMQ Broker
Red Hat Data Grid
Red Hat Openshift Data Foundation
Red Hat Satellite
Node HealthCheck Operator
Red Hat OpenShift Virtualization
Red Hat Ansible Automation Platform
OpenShift Dev Spaces
Migration Toolkit for Containers
OpenShift Pipelines
Red Hat Build of Keycloak
OpenShift AI
Red Hat OpenShift Lightspeed
Red Hat Trusted Artifact Signer
Red Hat build of Apache Camel
Cryostat
Red Hat Connectivity Link
Red Hat Enterprise Linux AI
Discovery
Ansible Automation Platform
Red Hat Hardened Images
Red Hat Build of Podman Desktop
Gatekeeper
Self-service automation portal
Red Hat Developer Hub
ПК СВ «Брест»
WebSocket
Platform V IAM SE

Версия ПО

8 (Red Hat Enterprise Linux)
4 (OpenShift Container Platform)
3 (Red Hat Quay)
7 (Red Hat AMQ Broker)
8 (Red Hat Data Grid)
4 (Red Hat Openshift Data Foundation)
6 (Red Hat Satellite)
9 (Red Hat Enterprise Linux)
- (Node HealthCheck Operator)
4 (Red Hat OpenShift Virtualization)
2 (Red Hat Ansible Automation Platform)
- (OpenShift Dev Spaces)
- (Migration Toolkit for Containers)
- (OpenShift Pipelines)
- (Red Hat Build of Keycloak)
- (OpenShift AI)
- (Red Hat OpenShift Lightspeed)
- (Red Hat Trusted Artifact Signer)
10 (Red Hat Enterprise Linux)
HawtIO 4 (Red Hat build of Apache Camel)
4 (Cryostat)
1 (Red Hat Connectivity Link)
3 (Red Hat Enterprise Linux AI)
2 (Discovery)
2.6 (Red Hat Ansible Automation Platform)
2 (Ansible Automation Platform)
- (Red Hat Hardened Images)
- (Red Hat Build of Podman Desktop)
3 (Gatekeeper)
2 (Self-service automation portal)
1.9 (Red Hat Developer Hub)
до 4.0.2 (ПК СВ «Брест»)
от 8.0.0 до 8.20.1 (WebSocket)
до 2.3.1 (Platform V IAM SE)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства
Сетевое программное средство
Сетевое средство
ПО для разработки ИИ
ПО программно-аппаратного средства
Средство защиты

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 10
Red Hat Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,6)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,4)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для WebSocket:
https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-45736
Для ПК СВ «Брест»:
обновление программного обеспечения, применение оперативного обновления ПК СВ «Брест» 4.0.2, предоставляемого в личном кабинете пользователя https://lk.astralinux.ru/ (https://wiki.astralinux.ru/x/ziLoD)
Для Platform V IAM SE:
Обновление до версии Platform V IAM SE 2.3.1

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 51%
0.00745
Низкий

4.4 Medium

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.4
ubuntu
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

CVSS3: 7.5
redhat
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

CVSS3: 4.4
nvd
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

msrc
2 месяца назад

ws: Uninitialized memory disclosure

CVSS3: 4.4
debian
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to ...

EPSS

Процентиль: 51%
0.00745
Низкий

4.4 Medium

CVSS3

4.6 Medium

CVSS2