faye websocket-driver是faye团队的一个WebSocket协议驱动库。 faye websocket-driver 0.8.1之前版本存在资源管理错误漏洞,该漏洞源于通过发送带有无止境标头列表的HTTP请求或响应,可使单连接消耗无限内存,导致接收进程内存耗尽。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| faye | websocket-driver-ruby | < 0.8.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| faye | websocket-driver-ruby | < 0.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54463 | websocket-driver: Memory exhaustion via abuse of protocol length headers | |
| CVE-2026-54464 | websocket-driver: Resource limit bypass via message compression | |
| CVE-2026-54466 | websocket-driver: Message corruption via abuse of protocol length headers | |
| CVE-2026-54490 | websocket-driver: Resource limit bypass via message compression |
No comments yet