Skip to content

UID2-7308: fix ws CVE-2026-48779 (HIGH) — upgrade to >=7.5.11#1031

Merged
sophia-chen-ttd merged 1 commit into
mainfrom
syw-UID2-7308-fix-ws-cve
Jun 16, 2026
Merged

UID2-7308: fix ws CVE-2026-48779 (HIGH) — upgrade to >=7.5.11#1031
sophia-chen-ttd merged 1 commit into
mainfrom
syw-UID2-7308-fix-ws-cve

Conversation

@sophia-chen-ttd

Copy link
Copy Markdown
Contributor

Summary

Fixes CVE-2026-48779 (HIGH): ws WebSocket memory exhaustion DoS via tiny frame fragments. Adds npm override ws>=7.5.11; lock file resolves to 8.21.0.

Test plan

  • CI vulnerability scan passes (Trivy should no longer report CVE-2026-48779)
  • Build and tests pass

…(UID2-7308)

CVE-2026-48779 (HIGH): ws WebSocket memory exhaustion DoS via tiny
frame fragments. Adds a npm override to force ws to >=7.5.11, resolving
to 8.21.0 in the lock file.
@sophia-chen-ttd sophia-chen-ttd merged commit 26e3992 into main Jun 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants