#1142415 node-websocket-driver: CVE-2026-54490 CVE-2026-54466

#1142415#5
Date:
2026-07-19 14:14:34 UTC
From:
To:
Hi,

The following vulnerabilities were published for node-websocket-driver.

CVE-2026-54490[0]:
| websocket-driver is a WebSocket protocol handler with pluggable I/O.
| Prior to 0.7.5, if this library is used with the permessage-deflate
| extension, a WebSocket server or client can be made to accept
| messages that are larger than the configured maximum message size
| because the limit is checked against the message frames' length
| headers, which give the size of the compressed data, not the size
| after decompression in lib/websocket/driver/hybi.js. This can lead
| to applications accepting larger messages than expected and
| exceeding their intended resource usage. This issue is fixed in
| version 0.7.5.


CVE-2026-54466[1]:
| websocket-driver is a WebSocket protocol handler with pluggable I/O.
| Prior to 0.7.5, the frame format in draft versions of the WebSocket
| protocol includes a length header that allows an arbitrarily large
| integer to be encoded as a sequence of bytes with the high bit set.
| By sending an indefinite sequence of bytes with values 0x80 or
| above, a client can make the server parse these bytes into an ever-
| growing integer in lib/websocket/driver/draft75.js; because
| JavaScript numbers are 64-bit floating point values, this number
| will eventually lose precision and lead to the subsequent payload
| being parsed incorrectly. This issue is fixed in version 0.7.5.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54490
https://www.cve.org/CVERecord?id=CVE-2026-54490
[1] https://security-tracker.debian.org/tracker/CVE-2026-54466
https://www.cve.org/CVERecord?id=CVE-2026-54466

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142415#8
Date:
2026-08-18 16:17:20 UTC
From:
To:
Hello,

Bug #1142415 in node-websocket-driver reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-websocket-driver/-/commit/4268e96871a3361a46cab56e921bf2a9d2c2ba0d

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142415

#1142415#13
Date:
2026-08-18 16:17:19 UTC
From:
To:
Hello,

Bug #1142415 in node-websocket-driver reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-websocket-driver/-/commit/4268e96871a3361a46cab56e921bf2a9d2c2ba0d

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142415

#1142415#18
Date:
2026-08-18 16:34:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-websocket-driver, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142415@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-websocket-driver package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 18 Aug 2026 18:15:44 +0200
Source: node-websocket-driver
Architecture: source
Version: 0.7.5+~cs0.6.14-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1142415
Changes:
 node-websocket-driver (0.7.5+~cs0.6.14-1) unstable; urgency=medium
 .
   * Team upload
   * Declare compliance with policy 4.7.4
   * Drop "Priority: optional"
   * New upstream version (Closes: #1142415, CVE-2026-54466)
Checksums-Sha1:
 220a015352183dec60983684227d19855f07ac45 2969 node-websocket-driver_0.7.5+~cs0.6.14-1.dsc
 b3277bd6d7ed5588e20ea73bf724fcbe44609075 7719 node-websocket-driver_0.7.5+~cs0.6.14.orig-http-parser-js.tar.gz
 bd6a9b1e3e527a8230ec414fe3161a1816f2f948 19740 node-websocket-driver_0.7.5+~cs0.6.14.orig-websocket-extensions.tar.gz
 938926b6c06665fa50b243bb36cfeb9d7aff52e3 26889 node-websocket-driver_0.7.5+~cs0.6.14.orig.tar.gz
 7e116664afd72449cff66132f128a2be6cfdceca 47820 node-websocket-driver_0.7.5+~cs0.6.14-1.debian.tar.xz
Checksums-Sha256:
 0baff5d08ef423963189d58712eca4c7895314e8f51fd7d690cd12b649f48c49 2969 node-websocket-driver_0.7.5+~cs0.6.14-1.dsc
 ab1672c31c6392825adaf4b61796a979beeea0daaffb10484f0da20238fd94e4 7719 node-websocket-driver_0.7.5+~cs0.6.14.orig-http-parser-js.tar.gz
 c8d7a574a851424c344ee062d3ce43782233b0c9b75d7551ac20a476e6497a69 19740 node-websocket-driver_0.7.5+~cs0.6.14.orig-websocket-extensions.tar.gz
 885fd3e3d9334c597cd3ee0b9801f22050feccba0a4963bca5f39a27cbff6fdd 26889 node-websocket-driver_0.7.5+~cs0.6.14.orig.tar.gz
 714fc2f6d797d1b0832c4601f78a1db48c4cef913abc70dd72eed92f23d861c4 47820 node-websocket-driver_0.7.5+~cs0.6.14-1.debian.tar.xz
Files:
 e7c894075adb2a83f3938a3d3d2199a9 2969 javascript optional node-websocket-driver_0.7.5+~cs0.6.14-1.dsc
 61e156b3adab1118a8cb36c0f816e3d7 7719 javascript optional node-websocket-driver_0.7.5+~cs0.6.14.orig-http-parser-js.tar.gz
 8f613a83f4a090270c9f10ef1824e7d0 19740 javascript optional node-websocket-driver_0.7.5+~cs0.6.14.orig-websocket-extensions.tar.gz
 c3cab35108086475f42bed4ab485fa16 26889 javascript optional node-websocket-driver_0.7.5+~cs0.6.14.orig.tar.gz
 67fd942d8fc0dfe940816a1436213859 47820 javascript optional node-websocket-driver_0.7.5+~cs0.6.14-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqEhXcACgkQ9tdMp8mZ
7ukbQQ/+PGpSbysE6uIpIohqojKRlA9EotllC8Pv3J4UHaWS5/2nPxo0AzJCl+9v
RhucsMF2m/Xf1Gmq7+UwG748I4u/GLdoz2iDz9PIveEh/5PpO3+Kxc2xtkPDXQI2
K515AnUdtVMkb8r7sSpOBP3grID2ujyykNtnBGpiMlvlQ0qwmcGqCt03CC+qU+rL
Iach1aPGZDI68/A/uMstMfTdWc0qiu0frQ+q0oc2eaVUr2EQ15OgfsDCS0y0pHNg
dJ++LcSGZKLS7etlMj9eqnSwIOLWkr4JdpQjSSQYIzQB1M96X1wP4EcafcSKeSgi
15i0xgwvmqVmL5K0qm6KVJAtsa1kCCdCPGSU9MtLGLkh0+6UJdxqmCcYpQU9B8RX
4NLd1ugs+wedAuXQ34wq5DzySP5lUHpavPLwadt65q+crOuiLmVSTwlLp6f9IqFu
abGRwpmHTGE6fYr1LQMrNwxPAMAyy/UB9xRkHabnp6Ad+hEbxDUQbkBtYyfFP5aA
2fvFN7PJbBJ9ocF3f9mOoLFuHY7gA0bysXKowEkQDl9oYlqj0s4jUX9C7JAQDGqU
4QyDzMhy9b/NNGfpIRZ7Pu3sxQB8pfYgT3owJs0Yj96nu2kqbMiZUSP+6R3Tkn0I
pBd2k8vDETU6aICFJPlYX1Nf8WZl4rX1zWc06HEIVotktUYK9Fw=
=pENe
-----END PGP SIGNATURE-----