CVE-2026-45736

ws: Uninitialized memory disclosure

mediumEPSS 51%
Severity
medium
kein öffentlicher PoC bekannt
50.7 %
Hoch — Modell sieht erhöhte Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-21 01:03 UTC
CWE-908

Weakness-Klassen (CWE)

  • CWE-908Base

    Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-22 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:40768
    • Reference: https://access.redhat.com/errata/RHSA-2026:40792
    • Reference: https://access.redhat.com/errata/RHSA-2026:41928
    • Affected: Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9 (+101)Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9 (+102)
  2. CVE Modified2026-07-20 12:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9 (+101)Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9 (+101)
  3. CVE Modified2026-07-09 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:36754
    • Reference: https://access.redhat.com/errata/RHSA-2026:36820
    • Affected: Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.9, Red Hat Discovery 2 (+34)Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9 (+35)

Beschreibung

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

Quelle: MSRC

Quellen & Referenzen