What it is
The `ws` package is a common WebSocket building block in Node.js apps, real-time dashboards, dev servers, and framework tooling. It matters most where your app runs a ws server that clients on the internet can connect to.
How it happens
The advisory affects ws release lines before the backported fixes in 5.2.4, 6.2.3, 7.5.10, and 8.17.1. The risky runtime shape is a ws server handling WebSocket upgrade requests where an excessive-header request crosses the affected code path.
What an attacker gets
If an affected ws server is deployed and reachable by untrusted clients, one crafted upgrade request can crash the Node.js process and take the service down until it restarts.
// what fixvibe reports
What FixVibe reports
Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Upgrade ws to the fixed version for the active release line, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild any server bundle, Docker image, devcontainer, or CI cache that installs it. If upgrade rollout needs time, validate temporary header-size or maxHeadersCount mitigations in staging without using crash-style traffic.
