websockets@8.1 vulnerabilities
An implementation of the WebSocket Protocol (RFC 6455 & 7692)
-
latest version
14.1
-
latest non vulnerable version
-
first published
11 years ago
-
latest version published
9 days ago
-
licenses detected
- [0.1,11.0)
Direct Vulnerabilities
Known vulnerabilities in the websockets package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Denial of Service (DoS). Header sizes are not properly validated which might result in some denial of service scenarios. This vulnerability is likely not exploitable. How to fix Denial of Service (DoS)? Upgrade |
[,10.0)
|
Affected versions of this package are vulnerable to Timing Attack when HTTP Basic Auth is enabled with How to fix Timing Attack? Upgrade |
[8.0,9.1)
|