GEM · JULY 2026 · EARLY WARNING

websocket-driver Gem Vulnerability: Memory Exhaustion Threat

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-GHHP-3QVG-889PSeverity: HIGH

The websocket-driver gem is reportedly vulnerable to memory exhaustion via abuse of protocol length headers, affecting versions prior to 0.8.1.

What happened

An early warning has been issued regarding a high severity vulnerability in the websocket-driver gem. This vulnerability, tracked under GHSA-GHHP-3QVG-889P, appears to allow memory exhaustion through the abuse of protocol length headers. Draft versions of the WebSocket protocol permit an attacker to send an indefinite sequence of bytes with high bit values, potentially causing the other peer to consume an unbounded amount of memory. This issue is under investigation, and it is recommended to upgrade to websocket-driver version 0.8.1 to mitigate the risk. For more detailed information, primary sources should be consulted.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If websocket-driver is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats