VulnSea

websocket-driver has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
6 prev 0

Products

  • websocket-driver 6
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

websocket-driver vulnerabilities

CVEs affecting websocket-driver, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-61666High· 7.5
1mo ago

websocket-driver is a WebSocket protocol handler with pluggable I/O

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing …

Twilightwebsocket-driver · websocket-driverEPSS 0.34%via NVD
CVE-2026-54463Medium
2mo ago

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: Memory exhaustion via abuse of protocol length headers

Sunlitwebsocket-driver · websocket-driverEPSS 0.34%via GHSA
CVE-2026-54464Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
CVE-2026-54465Medium
2mo ago

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: Memory exhaustion in HTTP header parser

Sunlitwebsocket-driver · websocket-driverEPSS 0.34%via GHSA
CVE-2026-54466Critical
2mo ago

websocket-driver: Message corruption via abuse of protocol length headers

websocket-driver: Message corruption via abuse of protocol length headers

Midnightwebsocket-driver · websocket-driverEPSS 0.22%via GHSA
CVE-2026-54490Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

Sunlitwebsocket-driver · websocket-driverEPSS 0.26%via GHSA
websocket-driver vulnerabilities (CVEs) · VulnSea