websocket-driver has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-54466Criticalwebsocket-driver: Message corruption via abuse of protocol length headers52CVE-2026-61666High· 7.5websocket-driver is a WebSocket protocol handler with pluggable I/O41CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression28CVE-2026-54465Mediumwebsocket-driver: Memory exhaustion in HTTP header parser28CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression28
websocket-driver vulnerabilities
CVEs affecting websocket-driver, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-61666High· 7.5websocket-driver is a WebSocket protocol handler with pluggable I/O
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing …
CVE-2026-54463Mediumwebsocket-driver: Memory exhaustion via abuse of protocol length headers
websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
CVE-2026-54465Mediumwebsocket-driver: Memory exhaustion in HTTP header parser
websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-54466Criticalwebsocket-driver: Message corruption via abuse of protocol length headers
websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression