CVE-2026-48779Patch(ws_project / ws)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ws_project ws systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770CWE-1050

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ws

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-06-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ws

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-26: 1Mentions · 2026-07-15: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-15: 1Technical Details · 2026-06-26: 106-2607-15
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • RazzReport@RazzReport
    Patch

    @vllm_project OpenHands is patching CVE-2026-48779. omnigent-ai/omnigent pushed security branches for shell parser fail-open fixes and callable tool upload guards. Agent frameworks are actively hardening against tool-execution vulnerabilities.

    Post summary

    OpenHands is addressing CVE-2026-48779 by applying shell parser fail‑open fixes and callable tool upload guards, indicating a vendor patch is available.

    2000054
    14 followersView on X
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-48779](https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7... https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7 #PatchManagement #Vulnerability #CVE

    Post summary

    The tweet announces CVE-2026-48779 and references a GitHub commit that presumably contains a patch, with no evidence of PoC, exploit code, or active exploitation.

    0000040
    11 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appws_projectws-node.js-

Explore more