{"id":"CVE-2026-54466","aliases":["GHSA-xv26-6w52-cph6"],"title":"websocket-driver: Message corruption via abuse of protocol length headers","summary":"websocket-driver: Message corruption via abuse of protocol length headers","severity":"critical","cwe":["CWE-130"],"vendor":"websocket-driver","product":"websocket-driver","ecosystem":"npm","affected":["websocket-driver < 0.7.5"],"patched":["websocket-driver 0.7.5"],"published":"2026-07-15","updated":"2026-07-15","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xv26-6w52-cph6","references":[{"url":"https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6"},{"url":"https://github.com/faye/websocket-driver-node/releases/tag/0.7.5"},{"url":"https://github.com/advisories/GHSA-xv26-6w52-cph6"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-15T22:46:58.790Z","epss":0.0038,"epssPercentile":0.29158,"slug":"CVE-2026-54466","body":"## Overview\n\n### Impact\n\nThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values `0x80` or above, a client can make the server parse these bytes into an ever-growing integer. Since JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly.\n\n### Patches\n\nThe issue has been patched in version 0.7.5 by rejecting the message if the length header exceeds the configured maximum message length. All users should upgrade to this version.\n\n### Workarounds\n\nNo known workarounds exist.\n\n### Acknowledgements\n\nThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.\n\n## Affected packages\n\n- `websocket-driver < 0.7.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `websocket-driver 0.7.5`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}