Your message dated Fri, 17 Jul 2026 09:18:50 +0000
with message-id <[email protected]>
and subject line Bug#1142271: fixed in node-ws 8.21.1+~cs14.19.1-1
has caused the Debian Bug report #1142271,
regarding node-ws: CVE-2026-62389
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142271: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142271
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-ws
Version: 8.21.0+~cs14.19.1-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/websockets/ws/issues/2331
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-ws.

CVE-2026-62389[0]:
| ws before 8.21.1 contains a memory exhaustion vulnerability in
| lib/receiver.js where the fragment guard only triggers when fragment
| count reaches maxFragments, allowing attackers to exhaust memory by
| sending incomplete fragmented WebSocket messages. Attackers can send
| a text frame with FIN=0 followed by continuation frames without
| completing the sequence, causing each fragment to be stored as a
| separate Buffer object with significant overhead, enabling denial of
| service through heap exhaustion.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-62389
    https://www.cve.org/CVERecord?id=CVE-2026-62389
[1] https://github.com/websockets/ws/issues/2331
[2] 
https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-ws
Source-Version: 8.21.1+~cs14.19.1-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-ws, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-ws package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 17 Jul 2026 11:07:20 +0200
Source: node-ws
Architecture: source
Version: 8.21.1+~cs14.19.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1142271
Changes:
 node-ws (8.21.1+~cs14.19.1-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version (Closes: #1142271, CVE-2026-62389)
Checksums-Sha1: 
 20d6b9f608ade53292ec101b1ecb893650ef764a 2925 node-ws_8.21.1+~cs14.19.1-1.dsc
 48464e4bf2ddfd17db13d845467f6070ffea4aa9 6013 
node-ws_8.21.1+~cs14.19.1.orig-types-ws.tar.gz
 4e0d6933802ccb18f663fd109c9e93a035859add 5016 
node-ws_8.21.1+~cs14.19.1.orig-wscat.tar.gz
 3818a3d4d75f5b2073609ff6e96428066b3930ce 88634 
node-ws_8.21.1+~cs14.19.1.orig.tar.gz
 14b99184862b926eb9cc1b3e0ad2fa8a022b7534 5412 
node-ws_8.21.1+~cs14.19.1-1.debian.tar.xz
Checksums-Sha256: 
 70454fc5774f398999176f7e1d607703b14087044933412feaaaf1defb832a73 2925 
node-ws_8.21.1+~cs14.19.1-1.dsc
 dc2763952a24bf15dc920830a2d2884c23bccc08a853e8556e34771401254fa5 6013 
node-ws_8.21.1+~cs14.19.1.orig-types-ws.tar.gz
 a779225d92fcceade8db9831b0f9f0830b2b20216e79f5fd303941817a267fe4 5016 
node-ws_8.21.1+~cs14.19.1.orig-wscat.tar.gz
 c6161ea6d989ec3c9a95d5a16a81c13cd2dd63501cf0793787c7cc02eb9a2865 88634 
node-ws_8.21.1+~cs14.19.1.orig.tar.gz
 951d640db62578c20a80d2af4e24a7a83401a5bf527cedd8734c544f5a93a32e 5412 
node-ws_8.21.1+~cs14.19.1-1.debian.tar.xz
Files: 
 ca61a83705fd3f6f526c73a047f97198 2925 javascript optional 
node-ws_8.21.1+~cs14.19.1-1.dsc
 b36d8736035a3f5c7b2fb62b2fbeca1a 6013 javascript optional 
node-ws_8.21.1+~cs14.19.1.orig-types-ws.tar.gz
 1ffc9b580c625f627939368a5c535c8a 5016 javascript optional 
node-ws_8.21.1+~cs14.19.1.orig-wscat.tar.gz
 a3a8a52943bdbb5bea0f53aee69bb349 88634 javascript optional 
node-ws_8.21.1+~cs14.19.1.orig.tar.gz
 eb2354160d3fcced16cc8fadff871272 5412 javascript optional 
node-ws_8.21.1+~cs14.19.1-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmpZ8ScACgkQ9tdMp8mZ
7umPdQ//c+68YI8+0MPaajb9l0/3cVoxdNCZVD7I6Nn3PljtCg/qbrB5YwzSWG3o
tRA5UDKepZQcjEQ9q6gTZXSanfu5D8aM1fqhc+Xc/l9DcY4EMXdnDQv+KvXK3XZC
rZjCEB/RZ8bF6UHuQlx4pNOyRe5lemSVFN0zCNS57ioYp9YsbevSzGdMY2FPyUny
aPiRNazTluFlpzDJuVJDJPz+uPF5J2J6FsTzdKHnrenWUQgI+iV9rwrXy15c1HYe
XId3QsHAit+Ea73tWSxtP9RRnCoozdfBIZ7J2DYIB1RGBZf8Ag8sL3PJ1tS+xHC7
CGIStn0gJ/2sjLwk7Uu0kj1V2ZXvCIhrs62KMw/54lecadfOz83KpbIDFNubsKbL
jNjUm+1LKdLBmLNVC2hINb/5aX01MLPQiIY3Hwpuaqg0v6cL1Z9+roy9YRWmbH+F
p0gLmDslxJJRW+Rs4XmUgXDHq4DK/bknrZqw2AOCapUWcrSvh0/0Hg5+M2wpSZBH
FCEjwEcD/PiB1Lgp+aE/sNwAnxWmVd7e9DoO67bUBxFJomUfNk6FBctpMGO0rwdW
csK6TpQt1CQZM5VMTU2L0M0nhPX3kFw325QQwYqfzEhx9534Ixm4PKdDtVi/HDBK
+KlY3cncGQ1FIIIbi1w6eG6rZcN6brTDkU0F/Fmmv9Iskga6bPM=
=b6k2
-----END PGP SIGNATURE-----

Attachment: pgpGvGjci32gs.pgp
Description: PGP signature


--- End Message ---

Reply via email to