websocket-driver: Memory exhaustion in HTTP header parser (CVE-2026-54465)
### Impact If this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the `WebSocket::Driver.server()` method, or, if it is used to complement a WebSocket client, then a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. ### Patches The issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
AI Analysis
Technical Summary
The websocket-driver Ruby library, used for handling WebSocket protocols with pluggable I/O, contains a vulnerability (CVE-2026-54465) in versions prior to 0.8.1. When used to implement a WebSocket server or client, an attacker can send an HTTP request or response containing a never-ending list of headers. This causes the receiving process to consume an unbounded amount of memory, potentially exhausting system resources and causing a denial of service. The issue is addressed and fixed in version 0.8.1.
Potential Impact
Exploitation of this vulnerability can lead to denial of service by exhausting the memory of the process handling WebSocket connections. There is no impact on confidentiality or integrity, but availability is severely affected due to potential process crashes or system instability.
Mitigation Recommendations
Upgrade websocket-driver to version 0.8.1 or later, where this vulnerability is fixed. No other mitigation is indicated or required.
websocket-driver: Memory exhaustion in HTTP header parser (CVE-2026-54465)
Description
### Impact If this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the `WebSocket::Driver.server()` method, or, if it is used to complement a WebSocket client, then a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. ### Patches The issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The websocket-driver Ruby library, used for handling WebSocket protocols with pluggable I/O, contains a vulnerability (CVE-2026-54465) in versions prior to 0.8.1. When used to implement a WebSocket server or client, an attacker can send an HTTP request or response containing a never-ending list of headers. This causes the receiving process to consume an unbounded amount of memory, potentially exhausting system resources and causing a denial of service. The issue is addressed and fixed in version 0.8.1.
Potential Impact
Exploitation of this vulnerability can lead to denial of service by exhausting the memory of the process handling WebSocket connections. There is no impact on confidentiality or integrity, but availability is severely affected due to potential process crashes or system instability.
Mitigation Recommendations
Upgrade websocket-driver to version 0.8.1 or later, where this vulnerability is fixed. No other mitigation is indicated or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8j3g-f24p-4mpw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54465"]
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a58b40e68715ace43d67cc8
Added to database: 07/16/2026, 10:35:58 UTC
Last enriched: 08/08/2026, 16:59:36 UTC
Last updated: 09/01/2026, 03:47:22 UTC
Views: 133
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.