QID 983857
QID 983857: Nodejs (npm) Security Update for uws (GHSA-hf5h-hh56-3vrg)
Affected versions of `uws` do not properly handle large websocket messages when `permessage-deflate` is enabled, which may result in a denial of service condition. If `uws` recieves a 256Mb websocket message when `permessage-deflate` is enabled, the server will compress the message prior to executing the length check, and subsequently extract the message prior to processing. This can result in a situation where an excessively large websocket message passes the length checks, yet still gets cast from a Buffer to a string, which will exceed v8's maximum string size and crash the process. ## Recommendation Update to version 0.10.9 or later. Alternatively, disable `permessage-deflate`.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
- GHSA-hf5h-hh56-3vrg -
github.com/advisories/GHSA-hf5h-hh56-3vrg
CVEs related to QID 983857
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hf5h-hh56-3vrg | uws |
|