Answer in brief
CVE-2026-54465 records a High severity (CVSS 7.5) vulnerability in websocket-driver: Memory exhaustion in HTTP header parser. The current sources do not mark it as known exploited. The current feed maps websocket-driver (rubygems), websocket-driver (rubygems). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps websocket-driver (rubygems), websocket-driver (rubygems). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:faye:websocket-driver:*:*:*:*:*:ruby:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| websocket-driverrubygems | <0.8.1 | 0.8.1 |
| websocket-driverrubygems | >=0 <0.8.1 | 0.8.1 |
Published upstream
Jul 15, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
### Impact If this library is used to implement a WebSocket server on top of a TCP server (rather than an HTTP server or framework) using the `WebSocket::Driver.server()` method, or, if it is used to complement a WebSocket client, then a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. ### Patches The issue has been patched in version 0.8.1, by limiting the total size of HTTP request/response lines and headers accepted by the parser to 32 kB. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.
Quoted source text, attributed separately from HOL analysis.