A AegiFlow
HIGHCVSS 8.9

CVE-2026-61666

websocket-driver-ruby: Denial of service via malformed Host header

Published
2026-07-21
Modified
2026-07-21
Aliases
GHSA-2x63-gw47-w4mm
Sources
github-advisory

Summary

### Impact If this library is used to implement a WebSocket server on top of a TCP server, by using the `WebSocket::Driver.server()` method, then a client can cause the server to crash by sending a `Host` header that is not a valid `host[:port]` string. When this happens, a `URI::InvalidURIError` exception is raised which is not caught, and this can cause the server process to crash if the application does not catch the error from the `parse()` method itself. ### Patches The issue has been patched in version 0.8.2 by making the request parser catch `URI::InvalidURIError` and enter an error state if the `Host` header is malformed. This means the request is considered invalid and should not establish a WebSocket connection. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.

Affected packages

EcosystemPackageAffected versionsFixed versions
RubyGemswebsocket-driver0.8.2

Remediation: Upgrade to 0.8.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.