Junglewise Threat Intelligence

CVE-2026-54490: faye websocket-driver resource limit bypass via message compression

CVE-2026-54490 · Severity: medium · CVSS 4 · Published 2026-07-17

Executive brief

A vulnerability in the websocket-driver library allows attackers to bypass configured message size limits when data compression is enabled. This means a malicious user could send messages that appear small but expand to a much larger size upon arrival, potentially exhausting server memory or processing power. This could lead to service slowdowns or crashes, impacting the availability of applications using this library.

Technical details

A resource limit bypass exists in websocket-driver (Node.js) prior to version 0.7.5. When the 'permessage-deflate' extension is active, the library validates the incoming message size against the 'Content-Length' header of the compressed WebSocket frame rather than the size of the decompressed payload. An attacker can exploit this by sending highly compressed 'zip bomb' style payloads that satisfy the length check but exceed memory limits upon decompression in 'lib/websocket/driver/hybi.js'. This can lead to excessive memory consumption and denial-of-service (DoS). The issue is resolved in version 0.7.5 by implementing length checks after extension processing.

Affected products

  • faye websocket-driver-node < 0.7.5

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory GHSA-mp7j-qc5w-4988 published
  • 2026-07-17: disclosed: CVE-2026-54490 published to NVD
  • 2026-07-17: patched: Fix released in version 0.7.5

References

Related threats