FixVibe

high

Denial of Service in 'ws' Library via Excessive HTTP Headers (CVE-2024-37890)

Affected ws server deployments can crash when processing WebSocket upgrade requests with excessive HTTP headers. FixVibe GitHub repo scans flag affected ws versions in npm manifests and lockfiles.

CVE-2024-37890GHSA-3h5v-q93c-6h6qCWE-476

Attacker Impact

An attacker can cause a Denial of Service (DoS) by crashing the Node.js process hosting the WebSocket server [S2]. By sending a specially crafted WebSocket upgrade request containing an unusually large number of HTTP headers, the attacker can force the application to terminate unexpectedly [S3]. This results in an immediate service interruption for all users connected to the affected instance [S2].

Root Cause

The vulnerability exists because the ws library fails to properly limit the number of HTTP headers processed during the initial WebSocket handshake [S2]. This lack of resource validation leads to a crash, identified as a NULL pointer dereference (CWE-476) in the underlying processing logic [S1]. The flaw allows a single malformed request to trigger a fatal runtime error, bypassing standard error handling [S1].

Remediation

To address this vulnerability, developers should update the ws package to version 5.2.4, 6.2.3, 7.5.10, 8.17.1, or higher, depending on the major version currently in use [S2]. Additionally, it is recommended to configure infrastructure-level protections, such as reverse proxies or Web Application Firewalls (WAFs), to enforce strict limits on the maximum number of HTTP headers allowed per request. This provides a defense-in-depth measure by filtering malicious handshake attempts before they reach the Node.js application layer.

How FixVibe Covers This

FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve ws to a version affected by CVE-2024-37890 / GHSA-3h5v-q93c-6h6q [S2], with the file, dependency path, version and fixed release.