Junglewise Threat Intelligence

CVE-2026-54464: Faye websocket-driver-ruby resource limit bypass in permessage-deflate

CVE-2026-54464 · Severity: medium · CVSS 4 · Published 2026-07-17

Technologies: websocket-driver (RubyGems). Vendors: RubyGems.

Executive brief

A vulnerability in a Ruby WebSocket library could allow an attacker to bypass configured message size limits when compression is enabled. By sending specially crafted compressed messages, an attacker can force the server or client to process much larger amounts of data than intended. This can lead to excessive memory or CPU consumption, potentially causing service instability or crashes.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in websocket-driver-ruby when used with the 'permessage-deflate' extension. The library validates the maximum message size against the compressed frame length header rather than the post-decompression payload size. An attacker can exploit this by sending highly compressed WebSocket frames that expand significantly upon decompression, bypassing '@max_length' restrictions. This can lead to uncontrolled memory allocation and denial-of-service. The issue is fixed in version 0.8.1 by implementing length checks after extension processing.

Affected products

  • faye websocket-driver-ruby < 0.8.1

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date
  • 2026-08-01: patched: Fixed in version 0.8.1

References

Related threats