websocket-driver: Memory exhaustion via abuse of protocol length headers (CVE-2026-54463)
### Impact The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values `0x80` or above, a server or client can make the other peer parse these bytes into an ever-growing integer. Since Ruby integers are arbitrary precision, this can be used to make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. ### Patches The issue has been patched in version 0.8.1. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
AI Analysis
Technical Summary
The websocket-driver Ruby library versions before 0.8.1 contain a vulnerability where draft versions of the WebSocket protocol include a length header that permits encoding an arbitrarily large integer with the high bit set. A malicious server or client can send an indefinite sequence of bytes with values 0x80 or higher, which the peer parses into a continuously growing Ruby integer. This behavior can cause unbounded memory consumption, leading to denial of service by exhausting system memory. The vulnerability is identified as CWE-770 (Allocation of Resources Without Limits or Throttling) and has a CVSS v3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The issue is resolved in websocket-driver version 0.8.1.
Potential Impact
Exploitation of this vulnerability can cause the affected Ruby process using websocket-driver to consume an unbounded amount of memory, potentially leading to denial of service due to out-of-memory conditions. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade websocket-driver to version 0.8.1 or later, where this vulnerability is fixed. No other mitigations are specified or required.
websocket-driver: Memory exhaustion via abuse of protocol length headers (CVE-2026-54463)
Description
### Impact The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values `0x80` or above, a server or client can make the other peer parse these bytes into an ever-growing integer. Since Ruby integers are arbitrary precision, this can be used to make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. ### Patches The issue has been patched in version 0.8.1. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The websocket-driver Ruby library versions before 0.8.1 contain a vulnerability where draft versions of the WebSocket protocol include a length header that permits encoding an arbitrarily large integer with the high bit set. A malicious server or client can send an indefinite sequence of bytes with values 0x80 or higher, which the peer parses into a continuously growing Ruby integer. This behavior can cause unbounded memory consumption, leading to denial of service by exhausting system memory. The vulnerability is identified as CWE-770 (Allocation of Resources Without Limits or Throttling) and has a CVSS v3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The issue is resolved in websocket-driver version 0.8.1.
Potential Impact
Exploitation of this vulnerability can cause the affected Ruby process using websocket-driver to consume an unbounded amount of memory, potentially leading to denial of service due to out-of-memory conditions. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade websocket-driver to version 0.8.1 or later, where this vulnerability is fixed. No other mitigations are specified or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ghhp-3qvg-889p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54463"]
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a58b41268715ace43d68287
Added to database: 07/16/2026, 10:36:02 UTC
Last enriched: 08/08/2026, 16:59:43 UTC
Last updated: 09/02/2026, 10:52:10 UTC
Views: 122
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.