Skip to content

websocket-driver: Message corruption via abuse of protocol length headers (CVE-2026-54466) #33623

Description

@TomekStolarz

Command

build

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

Severity - Critical
Description
Impact
The frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer. Since JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly.

Patches
The issue has been patched in version 0.7.5 by rejecting the message if the length header exceeds the configured maximum message length. All users should upgrade to this version

Recommendation
Upgrade websocket-driver from 0.7.4 to 0.7.5 to fix the vulnerability.

Minimal Reproduction

N/A
Affected version 20.3.x

Exception or Error


Your Environment

@angular-devkit/build-angular 20.3.32

Anything else relevant?

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions