CVE-2026-45736

Aliases:GHSA-58qx-3vcg-4xpx
Analyzed
Published: 15 May 2026, 14:53
Last modified:22 Jul 2026, 12:08

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.72% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

15 May 2026, 14:53
Published
Vulnerability first disclosed
22 Jul 2026, 12:08
Last Modified
Vulnerability information updated

Description

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

CVSS Metrics

  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.72% Percentile: 49%

Techniques & Countermeasures

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

  • CWE-824Access of Uninitialized Pointer

    The product accesses or uses a pointer that has not been initialized.

Affected Systems

  • Npmws

    ≥ 8.0.0, < 8.20.1

  • websocketsws

    ≥ 8.0.0, < 8.20.1

  • ws_projectws

    ≥ 8.0.0, < 8.20.1

References (20)