CVE-2026-61666Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2Technical Details · 2026-08-17: 208-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-61666 websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/web… https://www.cve.org/CVERecord?id=CVE-2026-61666 ----- Traducción: CVE-2026-61666 web… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑61666 in the websocket‑driver library, noting a malformed Host header parsing issue before version 0.8.2. No proof‑of‑concept, exploit, or evidence of active exploitation is provided.

    0000023
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-61666 websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/web… https://www.cve.org/CVERecord?id=CVE-2026-61666

    Post summary

    The message discloses that the websocket-driver library (pre‑0.8.2) mishandles a malformed Host header, providing a link to the CVE record.

    000001.4K
    58.0K followersView on X

Explore more