CVE-2026-45736

Aliases:GHSA-58qx-3vcg-4xpxDEBIAN-CVE-2026-45736CGA-2392-9rrp-v2r5CGA-28xm-29mw-q5hxCGA-2vwg-75rg-97rpCGA-332m-mp9g-4gjwCGA-38p5-c8w7-w8cfCGA-479c-2w98-x6p2CGA-4wc5-f3jh-f4pjCGA-57pg-hch4-qcgmCGA-5vj5-q4vf-9hp2CGA-68xw-26pg-pwh4CGA-6cw5-mj5g-wqp8CGA-7cx3-vg46-94gmCGA-7hgq-7v63-jv3gCGA-7mmp-7jhq-cgx2CGA-7q25-cwp9-rg2mCGA-8v93-5j53-qx7vCGA-8xjv-rfc4-pcwxCGA-94wm-v78m-m398CGA-96wh-vrcr-p9h6CGA-9p73-g7vp-xfq8CGA-9x6x-pm8x-236mCGA-c69x-ffq6-5pmjCGA-cc86-7pm2-p5phCGA-cghv-c5gv-6hm2CGA-cpw6-rjx6-c7h9CGA-fcvx-gcjv-cw33CGA-fgh9-9xq8-f29rCGA-fgqh-h8fx-pxc6CGA-frc8-7v8c-373rCGA-frvq-68vp-w25xCGA-g3x5-4qw3-v52jCGA-g46g-v23p-h372CGA-g724-4w8g-xwvrCGA-gg2p-qx73-6f2wCGA-ggj4-2xqx-gj8mCGA-gmr9-jmm8-pc7gCGA-gqqj-cm63-xj7hCGA-gx4f-g5x2-3m8fCGA-h52v-2xvc-vmqgCGA-h5fr-76cv-ch97CGA-hp49-c86c-r4f8CGA-hx5x-jxx2-23gpCGA-m369-fv7q-q366CGA-m4hv-qr7h-h3p4CGA-mcvh-7j82-r3vmCGA-mww3-4c8m-3wg7CGA-mx55-437c-p838CGA-p482-hfxc-x2cvCGA-p6xc-8mmp-8v82CGA-pgw2-vq7r-xg67CGA-phhr-f4wf-rqv3CGA-pmq6-86fm-mq4fCGA-pp4x-539v-h7jvCGA-pw83-5j8v-xg3rCGA-pwg6-w3q7-8j3jCGA-px9h-gwmm-fqpxCGA-253r-72m3-qvr8CGA-269x-9568-524mCGA-2c96-7fj9-5mpmCGA-2gx2-22cj-vmf8CGA-2q6p-w7pq-ppj4CGA-2rc7-fgx7-c38hCGA-32pf-jxhf-fqqmCGA-34gg-qq2r-5f98CGA-34vh-7p8x-5xr5CGA-36fv-4wfx-98jpCGA-3f26-9m7w-xjp3CGA-3f6r-w52h-xwxxCGA-3mc3-4w5x-856qCGA-3pj8-3px6-4c4rCGA-3q42-xr88-mf7wCGA-3rmg-pfhm-84rwCGA-3v2p-2qvm-wpcpCGA-3vgf-xm67-2gh7CGA-3wff-57j9-c89mCGA-3x92-9jw9-x9q8CGA-42p4-c6fv-v8hrCGA-535h-62hj-pq5gCGA-5hr9-wcq8-gv9jCGA-5j8w-fr99-7c24CGA-5pwm-mw69-gpr7CGA-5qxp-v379-822xCGA-5wmw-9w6p-w6cfCGA-6233-9m2w-pgmvCGA-66qh-wr9c-pxmcCGA-6jfw-3mh6-wq2cCGA-6jx2-4r35-5jx3CGA-6rv3-24gv-qm6hCGA-6wv7-f53w-6pvcCGA-7276-96fw-v96mCGA-73c5-6fmm-w6xfCGA-744c-hwx4-c43gCGA-74w5-prcm-jfwmCGA-794h-7jv8-8gq4CGA-7fcf-23gf-2q7gCGA-7gf2-4vjh-xf8jCGA-7ggc-xm73-6mrrCGA-7h4v-q5c2-xmxwCGA-7p3w-ghq9-8hqgCGA-7p79-2x4g-hvrqCGA-7vqr-wvh2-6rq6CGA-7w23-88w9-j8c9CGA-7wx3-x74f-mhq9CGA-7x3j-h4vm-695gCGA-84wh-rp84-88j9CGA-88qg-6qg9-p95vCGA-8cp5-4rqx-q5w5CGA-8ffr-3vc9-8xjgCGA-8pw9-75h8-pw77CGA-8v9q-w3h4-4vrgCGA-8w4h-qqv5-c323CGA-8xf9-hhjc-jh3vCGA-92fw-j9hc-22v2CGA-92rj-789q-3fwhCGA-975j-256v-r4cjCGA-9845-4r86-rwc3CGA-9vp2-pw67-j27jCGA-c2g7-j828-h5hhCGA-c5xw-5w74-7f63CGA-c97x-gwqv-7j45CGA-cfx4-4272-65g7CGA-cg6r-h75m-5qh3CGA-chcv-2662-pgc2CGA-cp5f-w85w-rp6qCGA-cqwm-8f7q-h2vwCGA-cr7x-jp87-p2v9CGA-cwx2-hhqf-4hrpCGA-cxpr-m9gv-86w9CGA-f6c2-6625-fh4wCGA-f8h6-hgpm-8v98CGA-ff85-44xj-h7j6CGA-ffcv-2p37-wmw6CGA-fg42-hf9f-6568CGA-frv8-hvhm-5qvjCGA-g5x3-9xv6-3687CGA-g7mq-q33h-8mf8CGA-g7vw-2538-jxqcCGA-gmg8-4pg4-8994CGA-gmgh-76h3-r5phCGA-gq2c-85gj-2754CGA-h26w-hr34-qmgrCGA-h3w8-mv27-5gv9CGA-h5v9-phq5-593xCGA-h8pc-w286-jwq4CGA-hf24-r83r-xwvqCGA-hgc6-mj79-gphwCGA-hh9v-qxpm-4f76CGA-hm4j-3hrv-grwwCGA-hqmc-cjpc-896rCGA-hvjm-5h99-m8r6CGA-j28v-vf3w-v6vfCGA-j64c-4rc2-hv93CGA-j6h8-qf55-x824CGA-j9v9-p2xh-9f6xCGA-jf99-jx6h-vf3wCGA-jh77-6cqq-vrchCGA-jmq6-647v-8xrqCGA-jv7v-85f9-gvqpCGA-jvm8-c3xg-m2r5CGA-jwh8-hx5h-frw4CGA-jwmr-mc28-4m5cCGA-jxw3-5vr6-436fCGA-m58v-5cmr-mg7hCGA-m763-x9wj-75h5CGA-mg6p-5wpx-7fgwCGA-mjrc-g2rh-832rCGA-mmgw-mf99-cm4rCGA-mp38-wmj4-r297CGA-mvp6-wf4w-h49hCGA-mxp6-3w62-cr6vCGA-p3jx-7fp7-53gqCGA-p42w-c76r-7jqpCGA-p5xw-p25f-9c5pCGA-pfwq-rgq9-584vCGA-pm8f-mh2c-v72jCGA-pr6r-4cm6-6pwhCGA-prc8-r5c4-46cmCGA-pwm6-g5vf-c3rhCGA-q38p-p376-8q27CGA-q6px-mw2r-mh25CGA-q8xr-vxmj-vxpqCGA-qcg2-3rqx-7gccCGA-qh67-v43r-x88xCGA-qrf5-3226-cvx9CGA-qvf9-252r-94xjCGA-qwj5-rhxf-hcfmCGA-qxv8-hjv2-6f26CGA-r265-hcqw-q5xqCGA-r5h3-5p74-frpgCGA-r6q9-mq5x-m245CGA-r8rj-3qj7-843gCGA-r98w-87jp-x79hCGA-r9r5-x76r-v6w2CGA-rf97-56h7-vc44CGA-rg2g-38vp-5h8pCGA-rj25-fwx2-wc28CGA-rm54-6wmm-fcqcCGA-rq7m-x46h-ww5hCGA-rx8v-h6vq-mp8gCGA-rxfg-q5m2-47gmCGA-v2x9-44wc-vmhhCGA-v45r-x9cm-2wvcCGA-v56f-hrwh-2qjfCGA-v5x9-27p8-6m66CGA-v65r-mr83-h3wgCGA-v739-v6j6-26xfCGA-v97j-79mw-9fx8CGA-vcxf-cwpg-fx57CGA-vj74-j72j-q7f3CGA-vmm6-wrvr-8qcqCGA-vmwh-rv2q-rg46CGA-vmww-77r3-m59pCGA-vq87-f6qh-94vxCGA-vr87-4frf-97jrCGA-w2mr-4423-xwm8CGA-w2wj-hvcr-fw3jCGA-w46w-h37x-r4xqCGA-w4qj-xj43-hvprCGA-w9v2-qh2h-rq2pCGA-wffh-7qwm-hx9qCGA-wg8g-39px-qqc7CGA-wgx3-5gpq-jp94CGA-whq2-459p-gwj7CGA-wrw9-3p24-c24rCGA-wvpj-w6wj-vhw9CGA-wxcx-j59h-3h5xCGA-x2vj-2cfx-8xpvCGA-x38g-g55c-q873CGA-x49c-fr9j-xfg7CGA-x4pc-g2wv-89f5CGA-x5hc-x3ww-75pfCGA-x66q-mr5f-8gg8CGA-xc3f-47m7-wrxvCGA-xcr5-5wqw-qpw9CGA-xghf-fm3c-wh4vCGA-xpxr-fff3-h573CGA-xrp9-577w-f3gwCGA-xxx4-q7mw-cf4rCGA-gcc3-7rvh-7h54CGA-jpfm-mpcx-5ph5CGA-cxqv-2pwm-8jcjCGA-pfqp-cj42-pxrqCGA-xxm4-j8qr-85cfCGA-3jxj-2gm4-7xvcCGA-4p3f-4pvf-8r2hCGA-7g88-mf9g-j7h4CGA-x2j4-qh6j-wcxgCGA-2qp7-qmr3-mg7fCGA-94q3-f4m6-q36q
Modified
Published: 15 May 2026, 14:53
Last modified:11 Sept 2026, 12:09

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.74% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

15 May 2026, 14:53
Published
Vulnerability first disclosed
11 Sept 2026, 12:09
Last Modified
Vulnerability information updated

Description

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

CVSS Metrics

  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.74% Percentile: 53%

Techniques & Countermeasures

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

  • CWE-824Access of Uninitialized Pointer

    The product accesses or uses a pointer that has not been initialized.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.4-r12

  • chainguardarangodb-3.12

    < 3.12.9.4-r11

  • chainguardargo-workflows-ui-3.6

    < 3.6.19-r7

  • chainguardargo-workflows-ui-3.7

    < 3.7.14-r4

  • chainguardcode-server

    < 4.121.0-r0

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddrupal-11.3

    < 11.3.13-r3

  • chainguardgemini-cli

    < 0.49.0-r4

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all | < 19.0.3-r1

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all | < 18.1.6-r15

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.1-r1 | < 19.1.7-r6

  • chainguardhomepage

    < 1.13.2-r0

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    all

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • chainguardkibana-7

    all

Showing first 50 affected entries in server-rendered view.

References (36)