---
id: CVE-2026-54463
aliases:
  - GHSA-ghhp-3qvg-889p
title: 'websocket-driver: Memory exhaustion via abuse of protocol length headers'
summary: 'websocket-driver: Memory exhaustion via abuse of protocol length headers'
severity: medium
cwe:
  - CWE-400
vendor: websocket-driver
product: websocket-driver
ecosystem: rubygems
affected:
  - websocket-driver < 0.8.1
patched:
  - websocket-driver 0.8.1
published: '2026-07-15'
updated: '2026-07-15'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-ghhp-3qvg-889p'
references:
  - url: >-
      https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p
  - url: 'https://github.com/faye/websocket-driver-ruby/releases/tag/0.8.1'
  - url: >-
      https://github.com/rubysec/ruby-advisory-db/blob/master/gems/websocket-driver/CVE-2026-54463.yml
  - url: 'https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-54463'
  - url: 'https://github.com/advisories/GHSA-ghhp-3qvg-889p'
tags:
  - ghsa
  - rubygems
ingestedAt: '2026-07-15T22:46:58.848Z'
epss: 0.00488
epssPercentile: 0.39418
---

## Overview

### Impact

The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values `0x80` or above, a server or client can make the other peer parse these bytes into an ever-growing integer. Since Ruby integers are arbitrary precision, this can be used to make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory.

### Patches

The issue has been patched in version 0.8.1. All users should upgrade to this version.

### Workarounds

No known workarounds exist.

### Acknowledgements

This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.

## Affected packages

- `websocket-driver < 0.8.1`

## Remediation

Upgrade to a patched release:

- `websocket-driver 0.8.1`
