A AegiFlow
HIGHCVSS 8.9

CVE-2026-61666

CVE-2026-61666 updated by NVD

Published
2026-07-21
Modified
2026-09-12
Sources
github-advisory, nvd

Summary

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
RubyGemswebsocket-driver0.8.2

Remediation: Upgrade to 0.8.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.