High severityNVD Advisory· Published Aug 17, 2026· Updated Sep 10, 2026
CVE-2026-61666
CVE-2026-61666
Description
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
websocket-driverRubyGems | < 0.8.2 | 0.8.2 |
Affected products
8- osv-coords6 versionspkg:apk/chainguard/gitlab-rails-ce-fips-19.3pkg:apk/chainguard/ruby4.0-rails-8.0pkg:apk/chainguard/pghero-fipspkg:apk/chainguard/gitlab-rails-ce-18.1pkg:apk/chainguard/pgheropkg:apk/chainguard/gitlab-rails-ce-19.3
< 19.3.1-r3+ 5 more
- (no CPE)range: < 19.3.1-r3
- (no CPE)range: < 8.0.5-r6
- (no CPE)range: < 3.8.0-r2
- (no CPE)range: < 18.1.6-r29
- (no CPE)range: < 3.8.0-r2
- (no CPE)range: < 19.3.1-r6
- Range: <0.8.2
- Range: <0.8.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.