Attacker Impact
An attacker can cause a Denial of Service (DoS) by crashing the Node.js process hosting the WebSocket server [S2]. By sending a specially crafted WebSocket upgrade request containing an unusually large number of HTTP headers, the attacker can force the application to terminate unexpectedly [S3]. This results in an immediate service interruption for all users connected to the affected instance [S2].
Root Cause
The vulnerability exists because the ws library fails to properly limit the number of HTTP headers processed during the initial WebSocket handshake [S2]. This lack of resource validation leads to a crash, identified as a NULL pointer dereference (CWE-476) in the underlying processing logic [S1]. The flaw allows a single malformed request to trigger a fatal runtime error, bypassing standard error handling [S1].
Remediation
To address this vulnerability, developers should update the ws package to version 5.2.4, 6.2.3, 7.5.10, 8.17.1, or higher, depending on the major version currently in use [S2]. Additionally, it is recommended to configure infrastructure-level protections, such as reverse proxies or Web Application Firewalls (WAFs), to enforce strict limits on the maximum number of HTTP headers allowed per request. This provides a defense-in-depth measure by filtering malicious handshake attempts before they reach the Node.js application layer.
How FixVibe Covers This
FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve ws to a version affected by CVE-2024-37890 / GHSA-3h5v-q93c-6h6q [S2], with the file, dependency path, version and fixed release.
