Source: node-ws
Version: 8.19.0+~cs14.19.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-ws.

CVE-2026-45736[0]:
| ws is an open source WebSocket client and server for Node.js. Prior
| to 8.20.1, the websocket.close() implementation is vulnerable to
| uninitialized memory disclosure when a TypedArray is passed as the
| reason argument. This vulnerability is fixed in 8.20.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-45736
    https://www.cve.org/CVERecord?id=CVE-2026-45736
[1] https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx
[2] 
https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to