CVE-2026-61666
websocket-driver: Denial of service via malformed Host header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.
| CWE | CWE-248 |
| Vendor | faye |
| Product | websocket-driver-ruby |
| Published | Aug 17, 2026 |
| Last Updated | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for faye websocket-driver-ruby
Be the first to know when new unknown vulnerabilities affecting faye websocket-driver-ruby are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
faye / websocket-driver-ruby
< 0.8.2