---
id: CVE-2026-54466
aliases:
  - GHSA-xv26-6w52-cph6
title: 'websocket-driver: Message corruption via abuse of protocol length headers'
summary: 'websocket-driver: Message corruption via abuse of protocol length headers'
severity: critical
cwe:
  - CWE-130
vendor: websocket-driver
product: websocket-driver
ecosystem: npm
affected:
  - websocket-driver < 0.7.5
patched:
  - websocket-driver 0.7.5
published: '2026-07-15'
updated: '2026-07-15'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-xv26-6w52-cph6'
references:
  - url: >-
      https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6
  - url: 'https://github.com/faye/websocket-driver-node/releases/tag/0.7.5'
  - url: 'https://github.com/advisories/GHSA-xv26-6w52-cph6'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-15T22:46:58.790Z'
epss: 0.0038
epssPercentile: 0.29253
---

## Overview

### Impact

The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values `0x80` or above, a client can make the server parse these bytes into an ever-growing integer. Since JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly.

### Patches

The issue has been patched in version 0.7.5 by rejecting the message if the length header exceeds the configured maximum message length. All users should upgrade to this version.

### Workarounds

No known workarounds exist.

### Acknowledgements

This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.

## Affected packages

- `websocket-driver < 0.7.5`

## Remediation

Upgrade to a patched release:

- `websocket-driver 0.7.5`
