A memory exhaustion DoS vulnerability exists in the ws WebSocket client and server for Node.js, affecting multiple version ranges. The vulnerability allows a peer to cause the remote peer to allocate excessive memory, leading to process termination due to OOM. This issue can be mitigated by verifying exposure in Node.js environments and applying patches or mitigations to prevent potential DoS attacks. Aff [truncated]
A vulnerability in the ws WebSocket client and server for Node.js could allow for uninitialized memory disclosure when a TypedArray is passed as the reason argument to the websocket.close() implementation. The CVE record was published on 2026-05-15T15:16:54.103Z and has not been modified since then. The NVD entry is currently Modified. Defenders responsible for Node.js environments using the ws library, e [truncated]