云虫漏洞库

CVE-2026-45736 - ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1. - 漏洞详情

漏洞编号:CVE-2026-45736

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-45736

CNNVD 编号:-

厂商/产品:ws_project / ws

影响范围:cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*

CWE:CWE-908

发布/更新时间:2026-05-15 / 2026-08-28

漏洞描述

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

相关链接

相关漏洞

« 返回首页