← Vulnerability feed

Vulnerability record · CVE-2026-45736 · published 15 May 2026

CVE-2026-45736: Ws project ws use of uninitialized resource vulnerability

WWs Project · Ws

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

7.5 CVSS 3.1 High EPSS 0.68% · top 49.7% CWE-908 · Use of uninitialized resourceCWE-824 · CWE-824
7.5CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
33References, 2 tagged exploit
11 Sep 2026Last modified by NVD

Description

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086 Patch
https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx ExploitPatchVendor Advisory
https://access.redhat.com/errata/RHSA-2026:26638
https://access.redhat.com/errata/RHSA-2026:26994
https://access.redhat.com/errata/RHSA-2026:27171
https://access.redhat.com/errata/RHSA-2026:29197
https://access.redhat.com/errata/RHSA-2026:33574
https://access.redhat.com/errata/RHSA-2026:34374
https://access.redhat.com/errata/RHSA-2026:36754
https://access.redhat.com/errata/RHSA-2026:36820
https://access.redhat.com/errata/RHSA-2026:37272
https://access.redhat.com/errata/RHSA-2026:40768
https://access.redhat.com/errata/RHSA-2026:40792
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:44235
https://access.redhat.com/errata/RHSA-2026:44263
https://access.redhat.com/errata/RHSA-2026:44267
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:48693
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:56928
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:57590
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:65126
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/errata/RHSA-2026:66545
https://access.redhat.com/errata/RHSA-2026:7655
https://access.redhat.com/security/cve/CVE-2026-45736
https://bugzilla.redhat.com/show_bug.cgi?id=2477914
https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx ExploitPatchVendor Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45736.json

Track CVE-2026-45736 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-48779Ws project ws uncontrolled resource consumption vulnerabilityws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7…EPSS 0.93%7.5CVE-2016-10542Ws project ws uncontrolled resource consumption vulnerabilityws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending…EPSS 7.5%7.5CVE-2016-10518Ws project ws memory buffer overflow vulnerabilityA vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame. T…EPSS 2.0%5.3CVE-2021-32640Ws project ws uncontrolled resource consumption vulnerabilityws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to…EPSS 2.8%7.8CVE-2026-85880Windows ALPC heap buffer overflow allows local privilege escalationA heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local acce…KEVEPSS 3.6%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed5.5CVE-2024-50302Linux kernel HID core uninitialized report buffer leaks kernel memoryThe Linux kernel HID core allocates a report buffer without zero-initializing it, so residual kernel memory can be exposed through crafted HID report…KEVEPSS 0.81%analysed5.5CVE-2024-29745Android Pixel firmware uninitialized data information disclosureCVE-2024-29745 is an information disclosure flaw in Android on Pixel devices caused by use of uninitialized data (CWE-908). A local attacker can read…KEVEPSS 0.48%analysed

Source: NIST National Vulnerability Database (record CVE-2026-45736), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.