๐Ÿ” CVE Alert

CVE-2026-61666

UNKNOWN 0.0

websocket-driver: Denial of service via malformed Host header

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.

CWE CWE-248
Vendor faye
Product websocket-driver-ruby
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for faye websocket-driver-ruby

Be the first to know when new unknown vulnerabilities affecting faye websocket-driver-ruby are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

faye / websocket-driver-ruby
< 0.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-2x63-gw47-w4mm github.com: https://github.com/faye/websocket-driver-ruby/commit/7d6fd87759a2fdc83590d3b49ffa661dc53fa128