faye-websocket
Standards-compliant WebSocket server and client
Activity
- Latest release
- 1y ago
- Total releases
- 44
- Cadence
- ~35 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Nov 28, 2011
| Version | Released | |
|---|---|---|
0.12.0
minor
|
0.12.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.11.4
patch
|
0.11.4
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.11.3
patch
|
0.11.3
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.11.2
patch
|
0.11.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.11.1
patch
|
0.11.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.11.0
minor
|
0.11.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.9
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.9
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.8
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.8
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.7
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.7
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.10.6
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.6
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.10.5
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.5
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.10.4
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.4
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.3
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.3
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.2
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.1
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.9.2
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.9.1
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.9.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.8.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.8.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.5
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.4
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.3
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.2
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.1
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.3
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.2
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.7
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.6
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.5
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.4
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2020-15133
GHSA-2v5c-755p-p4gv
Jul 31, 2020
Missing TLS certificate verification in faye-websocket
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
The This has been a requested feature in EventMachine for many years now; see for example #275, #378, and #814. In June 2020, em-http-request published an advisory related to this problem and fixed it by implementing TLS verification in their own codebase; although EventMachine does not implement certificate verification itself, it provides an extension point for the caller to implement it, called
After implementing verification in v1.1.6, em-http-request has elected to leave the
The latter case includes situations like talking to a non-public server using a self-signed certificate. We consider this use case to be "working by accident", rather than functionality that was actively supported, and it should be properly and explicitly supported instead. To that end, we have added two new options to the The
The
To get the new behaviour, please upgrade to v0.11.0 of the Rubygems package. There are, unfortunately, no workarounds for this issue, as you cannot enable For further background information on this issue, please see faye#524 and faye-websocket#129. We would like to thank Tero Marttila and Daniel Morsing for providing invaluable assistance and feedback on this issue. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
+ 26 more Show less
0.10.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.9.0
0.9.1
0.9.2
Fixed in
0.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev |