CVE-2026-45736

EUVD-2026-30543
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51.56%
Affected Products (NVD)
VendorProductVersion
ws_projectws
8.0.0 ≤
𝑥
< 8.20.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatCryostat 4 on RHEL 9
4.2.0-13 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1782761510 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.10
1783448184 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1782761244 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1782166952 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
10.0.109-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
8.0.128-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
9.0.118-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
1.22.22-18.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Migration Toolkit 1.8
1783690532 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.19
1784670101 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.20
1784724699 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.20
1784730857 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.21
1784127553 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.21
1784713741 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.22
1784144936 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.22
1785230147 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Dev Spaces 3.29
1782498475 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Dev Spaces 3.29
1782498792 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.4
1783327185 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
node-ws
bookworm
no-dsa
bullseye
postponed
forky
8.21.1+~cs14.19.1-1
fixed
sid
8.21.1+~cs14.19.1-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-ws
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage