Junglewise Threat Intelligence

CVE-2026-45736: websockets ws uninitialized memory disclosure in websocket.close

CVE-2026-45736 · Severity: medium · CVSS 4.4 · Published 2026-05-15

Technologies: ws (npm). Vendors: npm.

Executive brief

The ws library is a widely-used WebSocket client and server for Node.js. When the close() method is called with a TypedArray as the reason argument, it fails to properly clear sensitive memory, potentially leaking uninitialized data to the remote peer. While the vulnerability requires misuse of the API (passing a TypedArray instead of a string or Buffer), it could expose sensitive server memory in applications that use this pattern.

Technical details

The vulnerability is a use-of-uninitialized-resource (CWE-908) flaw in the websocket.close() implementation. When a TypedArray (e.g., Float32Array) is passed as the reason argument instead of a string or Buffer, the code does not correctly validate or handle the type, resulting in disclosure of uninitialized memory from a Buffer.allocUnsafe()-allocated buffer. The attack requires the attacker to control the reason argument passed to close(), which typically requires application-level misuse; no user interaction is required. An attacker can read sensitive data (e.g., API keys, internal buffers) from the server process memory that is transmitted to the remote peer. The vulnerability was fixed in ws@8.20.1 by adding stricter validation for the reason argument type.

Affected products

  • websockets ws >=8.0.0, <8.20.1

Timeline

  • 2026-05-18: disclosed
  • 2026-05-18: patched: Fixed in ws@8.20.1 (commit c0327ec15a54d701eb6ccefaa8bef328cfc03086)

References

Related threats