websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.

Project Subscriptions

Vendors Products
Websocket-driver-ruby Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2x63-gw47-w4mm websocket-driver-ruby: Denial of service via malformed Host header
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Faye
Faye websocket-driver-ruby
Vendors & Products Faye
Faye websocket-driver-ruby

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.
Title websocket-driver: Denial of service via malformed Host header
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-17T17:00:52.736Z

Reserved: 2026-07-10T18:25:21.467Z

Link: CVE-2026-61666

cve-icon Vulnrichment

Updated: 2026-08-17T17:00:25.644Z

cve-icon NVD

Status : Received

Published: 2026-08-17T17:16:39.917

Modified: 2026-08-17T17:16:39.917

Link: CVE-2026-61666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T17:45:03Z

Weaknesses