A memory exhaustion DoS vulnerability was found in ws, an open source WebSocket client and server for Node.js. The vulnerability affects multiple version ranges: 1.1.0 up to (but not including) 5.2.5, 6.0.0 up to 6.2.4, 7.0.0 up to 7.5.11, and 8.0.0 up to 8.21.0. An attacker can cause a remote peer to allocate and hold structural wrappers that consume more memory than the default documented message-size l [truncated]
CVE-2026-45736 affects ws, the open source WebSocket client and server for Node.js. The issue is an uninitialized memory disclosure in websocket.close() when a TypedArray is supplied as the reason argument. The fix is in ws 8.20.1. The CVE was published on 2026-05-15 and last modified on 2026-05-18.