---
id: CVE-2026-54465
aliases:
  - GHSA-8j3g-f24p-4mpw
title: 'websocket-driver: Memory exhaustion in HTTP header parser'
summary: 'websocket-driver: Memory exhaustion in HTTP header parser'
severity: medium
cwe:
  - CWE-400
vendor: websocket-driver
product: websocket-driver
ecosystem: rubygems
affected:
  - websocket-driver < 0.8.1
patched:
  - websocket-driver 0.8.1
published: '2026-07-15'
updated: '2026-07-15'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-8j3g-f24p-4mpw'
references:
  - url: >-
      https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw
  - url: 'https://github.com/faye/websocket-driver-ruby/releases/tag/0.8.1'
  - url: >-
      https://github.com/rubysec/ruby-advisory-db/blob/master/gems/websocket-driver/CVE-2026-54465.yml
  - url: 'https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-54465'
  - url: 'https://github.com/advisories/GHSA-8j3g-f24p-4mpw'
tags:
  - ghsa
  - rubygems
ingestedAt: '2026-07-15T22:46:58.810Z'
epss: 0.00488
epssPercentile: 0.39405
---

## Overview

### Impact

If this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the `WebSocket::Driver.server()` method, or, if it is used to complement a WebSocket client, then a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory.

### Patches

The issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version.

### Workarounds

No known workarounds exist.

### Acknowledgements

This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.

## Affected packages

- `websocket-driver < 0.8.1`

## Remediation

Upgrade to a patched release:

- `websocket-driver 0.8.1`
