{"id":"GHSA-58qx-3vcg-4xpx","summary":"ws: Uninitialized memory disclosure","details":"### Impact\n\nThe `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.\n\n### Proof of concept\n\n```js\nimport { deepStrictEqual } from 'node:assert';\nimport { WebSocket, WebSocketServer } from 'ws';\n\nconst wss = new WebSocketServer(\n  { port: 0, skipUTF8Validation: true },\n  function () {\n    const { port } = wss.address();\n    const ws = new WebSocket(`ws://localhost:${port}`, {\n      skipUTF8Validation: true\n    });\n\n    ws.on('close', function (code, reason) {\n      deepStrictEqual(reason, Buffer.alloc(80));\n    });\n  }\n);\n\nwss.on('connection', function (ws) {\n  ws.close(1000, new Float32Array(20));\n});\n```\n\n### Patches\n\nThe vulnerability was fixed in ws@8.20.1 (https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086).\n\n### Credits\n\nCredit for the private and responsible disclosure of this issue goes to [Nikita Skovoroda](https://github.com/ChALkeR).\n\n### Remarks\n\nAlthough the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.\n\n### Resources\n\n- https://github.com/advisories/GHSA-58qx-3vcg-4xpx\n- https://www.cve.org/CVERecord?id=CVE-2026-45736","aliases":["CVE-2026-45736"],"modified":"2026-07-17T21:07:02.177240714Z","published":"2026-05-18T19:02:40Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-18T19:02:40Z","nvd_published_at":"2026-05-15T15:16:54Z","cwe_ids":["CWE-908"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45736"},{"type":"WEB","url":"https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086"},{"type":"PACKAGE","url":"https://github.com/websockets/ws"}],"affected":[{"package":{"name":"ws","ecosystem":"npm","purl":"pkg:npm/ws"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.20.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-58qx-3vcg-4xpx/GHSA-58qx-3vcg-4xpx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}