CVE-2026-54466
Reported by GitHub_M · Published July 17, 2026
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| faye | websocket-driver-node | < 0.7.5 |
| faye | websocket-driver-node | < 0.7.5, < 0.7.5, < 0.7.5 |
| chainguard | gitlab-rails-ce-fips-18.1 | 0, 0, 0 |
| chainguard | arangodb-3.12 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.1 | 0, 0, 0 |
| chainguard | arangodb-3.11 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.0 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-18.1 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-19.0 | 0, 0, 0 |
| npm | websocket-driver | 0 |
| chainguard | gitlab-rails-ce-19.1 | 0, 0, 0 |
Timeline
- Jul 15, 2026 CVE Published
- Jul 18, 2026 EPSS Score
- Jul 18, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
References
- https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6 x_refsource_CONFIRM
- https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-54466 advisory
- https://github.com/advisories/GHSA-xv26-6w52-cph6 advisory
- https://github.com/faye/websocket-driver-node/releases/tag/0.7.5 url