websocket-driver
WebSocket protocol handler with pluggable I/O
Activity
- Latest release
- 2mo ago
- Total releases
- 34
- Cadence
- ~2 months
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- May 04, 2013
| Version | Released | |
|---|---|---|
0.8.2
patch
| ||
0.8.1
patch
1 CVE
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.7
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.6
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.5
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.4
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.3
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.2
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.1
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.5
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.4
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.3
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.2
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.1
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.4
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.3
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.2
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.1
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.5
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.4
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.3
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.2
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.1
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.2
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.3
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.1
patch
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.0
minor
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.0
initial
4 CVEs
CVE-2026-61666
GHSA-2x63-gw47-w4mm
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server, by using the PatchesThe issue has been patched in version 0.8.2 by making the request parser catch WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
Fixed in
0.8.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54465
GHSA-8j3g-f24p-4mpw
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Medium
Network
Low
None
None
ImpactIf this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the PatchesThe issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54464
GHSA-33ph-fccm-39pj
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Medium
Network
Low
None
None
ImpactIf this library is used in tandem with the PatchesThe issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54463
GHSA-ghhp-3qvg-889p
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Medium
Network
Low
None
None
ImpactThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values PatchesThe issue has been patched in version 0.8.1. All users should upgrade to this version. WorkaroundsNo known workarounds exist. AcknowledgementsThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team. Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
+ 20 more Show less
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
Fixed in
0.8.1
References
Updated Sep 10, 2026 · Source: OSV.dev |