GHSA-ghhp-3qvg-889p
Dashboard / Vulnerabilities / GHSA-ghhp-3qvg-889p
Summary: websocket-driver: Memory exhaustion via abuse of protocol length headers
Details: ### Impact The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values `0x80` or above, a server or client can make the other peer parse these bytes into an ever-growing integer. Since Ruby integers are arbitrary precision, this can be used to make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. ### Patches The issue has been patched in version 0.8.1. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
References: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p, https://nvd.nist.gov/vuln/detail/CVE-2026-54463, https://github.com/faye/websocket-driver-ruby/commit/d0141f041f6e3677a951255d547a313e732ccbe0, https://github.com/faye/websocket-driver-ruby, https://github.com/faye/websocket-driver-ruby/releases/tag/0.8.1, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/websocket-driver/CVE-2026-54463.yml, https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-54463
Affected packages
Package
Name: websocket-driver
Purl: pkg:gem/websocket-driver
Affected ranges
Type: ECOSYSTEM
Events:
