Vulnerability record · CVE-2021-32640 · published 25 May 2021
CVE-2021-32640: Ws project ws uncontrolled resource consumption vulnerability
WWs Project · Ws
ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in [email protected] (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.
Description
ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in [email protected] (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff | PatchThird Party Advisory |
| https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693 | ExploitMitigationPatchThird Party Advisory |
| https://lists.apache.org/thread.html/rdfa7b6253c4d6271e31566ecd5f30b7ce1b8fb2c89d52b8c4e0f4e30%40%3Ccommits.tinkerpop.ap | |
| https://security.netapp.com/advisory/ntap-20210706-0005/ | Third Party Advisory |
| https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff | PatchThird Party Advisory |
| https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693 | ExploitMitigationPatchThird Party Advisory |
| https://lists.apache.org/thread.html/rdfa7b6253c4d6271e31566ecd5f30b7ce1b8fb2c89d52b8c4e0f4e30%40%3Ccommits.tinkerpop.ap | |
| https://security.netapp.com/advisory/ntap-20210706-0005/ | Third Party Advisory |
Track CVE-2021-32640 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32640), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.