- Package:
- src:node-websocket-driver
- Source:
- src:node-websocket-driver
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-18 16:35:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for node-websocket-driver. CVE-2026-54490[0]: | websocket-driver is a WebSocket protocol handler with pluggable I/O. | Prior to 0.7.5, if this library is used with the permessage-deflate | extension, a WebSocket server or client can be made to accept | messages that are larger than the configured maximum message size | because the limit is checked against the message frames' length | headers, which give the size of the compressed data, not the size | after decompression in lib/websocket/driver/hybi.js. This can lead | to applications accepting larger messages than expected and | exceeding their intended resource usage. This issue is fixed in | version 0.7.5. CVE-2026-54466[1]: | websocket-driver is a WebSocket protocol handler with pluggable I/O. | Prior to 0.7.5, the frame format in draft versions of the WebSocket | protocol includes a length header that allows an arbitrarily large | integer to be encoded as a sequence of bytes with the high bit set. | By sending an indefinite sequence of bytes with values 0x80 or | above, a client can make the server parse these bytes into an ever- | growing integer in lib/websocket/driver/draft75.js; because | JavaScript numbers are 64-bit floating point values, this number | will eventually lose precision and lead to the subsequent payload | being parsed incorrectly. This issue is fixed in version 0.7.5. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54490 https://www.cve.org/CVERecord?id=CVE-2026-54490 [1] https://security-tracker.debian.org/tracker/CVE-2026-54466 https://www.cve.org/CVERecord?id=CVE-2026-54466 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1142415 in node-websocket-driver reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-websocket-driver/-/commit/4268e96871a3361a46cab56e921bf2a9d2c2ba0d (this message was generated automatically) -- Greetings https://bugs.debian.org/1142415
Hello, Bug #1142415 in node-websocket-driver reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-websocket-driver/-/commit/4268e96871a3361a46cab56e921bf2a9d2c2ba0d (this message was generated automatically) -- Greetings https://bugs.debian.org/1142415
We believe that the bug you reported is fixed in the latest version of node-websocket-driver, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1142415@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-websocket-driver package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Tue, 18 Aug 2026 18:15:44 +0200 Source: node-websocket-driver Architecture: source Version: 0.7.5+~cs0.6.14-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1142415 Changes: node-websocket-driver (0.7.5+~cs0.6.14-1) unstable; urgency=medium . * Team upload * Declare compliance with policy 4.7.4 * Drop "Priority: optional" * New upstream version (Closes: #1142415, CVE-2026-54466) Checksums-Sha1: 220a015352183dec60983684227d19855f07ac45 2969 node-websocket-driver_0.7.5+~cs0.6.14-1.dsc b3277bd6d7ed5588e20ea73bf724fcbe44609075 7719 node-websocket-driver_0.7.5+~cs0.6.14.orig-http-parser-js.tar.gz bd6a9b1e3e527a8230ec414fe3161a1816f2f948 19740 node-websocket-driver_0.7.5+~cs0.6.14.orig-websocket-extensions.tar.gz 938926b6c06665fa50b243bb36cfeb9d7aff52e3 26889 node-websocket-driver_0.7.5+~cs0.6.14.orig.tar.gz 7e116664afd72449cff66132f128a2be6cfdceca 47820 node-websocket-driver_0.7.5+~cs0.6.14-1.debian.tar.xz Checksums-Sha256: 0baff5d08ef423963189d58712eca4c7895314e8f51fd7d690cd12b649f48c49 2969 node-websocket-driver_0.7.5+~cs0.6.14-1.dsc ab1672c31c6392825adaf4b61796a979beeea0daaffb10484f0da20238fd94e4 7719 node-websocket-driver_0.7.5+~cs0.6.14.orig-http-parser-js.tar.gz c8d7a574a851424c344ee062d3ce43782233b0c9b75d7551ac20a476e6497a69 19740 node-websocket-driver_0.7.5+~cs0.6.14.orig-websocket-extensions.tar.gz 885fd3e3d9334c597cd3ee0b9801f22050feccba0a4963bca5f39a27cbff6fdd 26889 node-websocket-driver_0.7.5+~cs0.6.14.orig.tar.gz 714fc2f6d797d1b0832c4601f78a1db48c4cef913abc70dd72eed92f23d861c4 47820 node-websocket-driver_0.7.5+~cs0.6.14-1.debian.tar.xz Files: e7c894075adb2a83f3938a3d3d2199a9 2969 javascript optional node-websocket-driver_0.7.5+~cs0.6.14-1.dsc 61e156b3adab1118a8cb36c0f816e3d7 7719 javascript optional node-websocket-driver_0.7.5+~cs0.6.14.orig-http-parser-js.tar.gz 8f613a83f4a090270c9f10ef1824e7d0 19740 javascript optional node-websocket-driver_0.7.5+~cs0.6.14.orig-websocket-extensions.tar.gz c3cab35108086475f42bed4ab485fa16 26889 javascript optional node-websocket-driver_0.7.5+~cs0.6.14.orig.tar.gz 67fd942d8fc0dfe940816a1436213859 47820 javascript optional node-websocket-driver_0.7.5+~cs0.6.14-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqEhXcACgkQ9tdMp8mZ 7ukbQQ/+PGpSbysE6uIpIohqojKRlA9EotllC8Pv3J4UHaWS5/2nPxo0AzJCl+9v RhucsMF2m/Xf1Gmq7+UwG748I4u/GLdoz2iDz9PIveEh/5PpO3+Kxc2xtkPDXQI2 K515AnUdtVMkb8r7sSpOBP3grID2ujyykNtnBGpiMlvlQ0qwmcGqCt03CC+qU+rL Iach1aPGZDI68/A/uMstMfTdWc0qiu0frQ+q0oc2eaVUr2EQ15OgfsDCS0y0pHNg dJ++LcSGZKLS7etlMj9eqnSwIOLWkr4JdpQjSSQYIzQB1M96X1wP4EcafcSKeSgi 15i0xgwvmqVmL5K0qm6KVJAtsa1kCCdCPGSU9MtLGLkh0+6UJdxqmCcYpQU9B8RX 4NLd1ugs+wedAuXQ34wq5DzySP5lUHpavPLwadt65q+crOuiLmVSTwlLp6f9IqFu abGRwpmHTGE6fYr1LQMrNwxPAMAyy/UB9xRkHabnp6Ad+hEbxDUQbkBtYyfFP5aA 2fvFN7PJbBJ9ocF3f9mOoLFuHY7gA0bysXKowEkQDl9oYlqj0s4jUX9C7JAQDGqU 4QyDzMhy9b/NNGfpIRZ7Pu3sxQB8pfYgT3owJs0Yj96nu2kqbMiZUSP+6R3Tkn0I pBd2k8vDETU6aICFJPlYX1Nf8WZl4rX1zWc06HEIVotktUYK9Fw= =pENe -----END PGP SIGNATURE-----