FixVibe

// 代码 / 聚焦

ws Excessive-Header DoS Advisory

Affected ws server runtimes can crash when upgrade requests carry too many headers.

What it is

The `ws` package is a common WebSocket building block in Node.js apps, real-time dashboards, dev servers, and framework tooling. It matters most where your app runs a ws server that clients on the internet can connect to.

How it happens

The advisory affects ws release lines before the backported fixes in 5.2.4, 6.2.3, 7.5.10, and 8.17.1. The risky runtime shape is a ws server handling WebSocket upgrade requests where an excessive-header request crosses the affected code path.

What an attacker gets

If an affected ws server is deployed and reachable by untrusted clients, one crafted upgrade request can crash the Node.js process and take the service down until it restarts.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade ws to the fixed version for the active release line, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild any server bundle, Docker image, devcontainer, or CI cache that installs it. If upgrade rollout needs time, validate temporary header-size or maxHeadersCount mitigations in staging without using crash-style traffic.

// 在你自己的應用上跑一遍

放心继續發布,FixVibe 持續幫你看守風险。

Connect a GitHub repo to check its code, dependencies and workflows.

源代码
198
本類别中触發的测試
模塊
155
專属 源代码 检查
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 最新检查 · 实用修複 · 安心發布

ws Excessive-Header DoS Advisory: what it is and how to fix it · FixVibe