Junglewise Threat Intelligence

CVE-2026-62389: websockets ws memory exhaustion in lib/receiver.js

CVE-2026-62389 · Severity: high · CVSS 7.5 · Published 2026-07-15

Technologies: Websockets Ws.

Executive brief

The 'ws' library, a popular WebSocket implementation for Node.js, is vulnerable to a denial-of-service attack. An unauthenticated remote attacker can crash a server by sending a large number of incomplete message fragments, which exhausts the server's available memory. This can lead to service outages and impact the availability of applications relying on this library for real-time communication.

Technical details

A memory exhaustion vulnerability exists in the 'ws' library's receiver logic (lib/receiver.js) due to insufficient default limits on message fragments. An attacker can initiate a text frame with the FIN bit set to 0 and follow it with numerous small continuation frames without ever completing the sequence. Because each fragment is stored as a separate Buffer object with significant internal overhead, the server's heap memory can be exhausted even if the total payload size remains below the 'maxPayload' limit. The vulnerability is exploited by keeping the fragment count just below the default 'maxFragments' threshold across multiple concurrent connections. The issue is addressed in version 8.21.1 by lowering the default values for 'maxBufferedChunks' and 'maxFragments' and ensuring empty fragments are counted toward these limits.

Affected products

  • websockets ws < 8.21.1

Timeline

  • 2026-06-04: disclosed: Vulnerability reported to maintainers via email.
  • 2026-07-14: patched: Version 8.21.1 released.
  • 2026-07-15: advisory: CVE-2026-62389 published.

References