Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45736

Опубликовано: 15 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

A flaw was found in ws, an open source WebSocket client and server for Node.js. The websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This can lead to the disclosure of sensitive information from uninitialized memory.

Отчет

This Important vulnerability in the ws WebSocket library for Node.js could lead to sensitive information disclosure. The flaw occurs when a TypedArray is specifically provided as the reason argument to the websocket.close() function, potentially exposing uninitialized memory. Red Hat products utilizing this library may be affected if their implementations allow for such a crafted close() call.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-openshift-console-plugin-rhel9Affected
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4grafana-infinity-datasource-npmNot affected
Cryostat 4wsNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleAffected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorAffected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-pf5-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2477914ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`

EPSS

Процентиль: 51%
0.00745
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

CVSS3: 4.4
nvd
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

msrc
2 месяца назад

ws: Uninitialized memory disclosure

CVSS3: 4.4
debian
3 месяца назад

ws is an open source WebSocket client and server for Node.js. Prior to ...

CVSS3: 4.4
github
3 месяца назад

ws: Uninitialized memory disclosure

EPSS

Процентиль: 51%
0.00745
Низкий

7.5 High

CVSS3