← Vulnerability feed

Vulnerability record · CVE-2021-32640 · published 25 May 2021

CVE-2021-32640: Ws project ws uncontrolled resource consumption vulnerability

WWs Project · Ws

ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in [email protected] (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.

5.3 CVSS 3.1 Medium EPSS 2.8% · top 14.0% CWE-400 · Uncontrolled resource consumption
5.3CVSS 3.1 base score, v2 5.0
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in [email protected] (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32640 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed9.8CVE-2021-26707Merge-deep project merge-deep prototype pollution vulnerabilityThe merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These …EPSS 1.9%9.8CVE-2021-23383Handlebarsjs handlebars prototype pollution vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from a…EPSS 4.5%9.8CVE-2021-20231Gnutls use after free vulnerabilityA flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.EPSS 3.8%8.8CVE-2022-21703Grafana cross-site request forgery vulnerabilityGrafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…EPSS 2.3%8.7CVE-2022-31097Grafana Unified Alerting stored XSS allows editor-to-admin privilege escalationGrafana 8.x and 9.x branches before 9.0.3, 8.5.9, 8.4.10 and 8.3.10 contain a stored cross-site scripting flaw in the Unified Alerting feature. An at…EPSS 69%analysed8.3CVE-2020-14664Oracle jdk vulnerabilityVulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to ex…EPSS 4.2%8.3CVE-2020-14583Oracle openjdk vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2021-32640), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.