websocket-driver npm Package Vulnerability: Early Warning
An early warning has been issued regarding a vulnerability in the websocket-driver npm package, which reportedly allows message corruption via abuse of protocol length headers. Users of versions prior to 0.7.5 are advised to upgrade.
What happened
The websocket-driver npm package is under investigation for a vulnerability that may allow message corruption through the abuse of protocol length headers. This issue could lead to payloads being parsed incorrectly. The vulnerability has been patched in version 0.7.5 of the package. It is recommended that users upgrade to this version to mitigate potential risks. For more detailed information, please consult the primary sources provided.
How 0Day mitigates this
websocket-driver is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.