VDB
KO
HIGH

GHSA-2x63-gw47-w4mm

websocket-driver-ruby: Denial of service via malformed Host header

Quick fix

GHSA-2x63-gw47-w4mm — websocket-driver: upgrade to the fixed version with the command below.

bundle update websocket-driver

Details

### Impact

If this library is used to implement a WebSocket server on top of a TCP server, by using the `WebSocket::Driver.server()` method, then a client can cause the server to crash by sending a `Host` header that is not a valid `host[:port]` string. When this happens, a `URI::InvalidURIError` exception is raised which is not caught, and this can cause the server process to crash if the application does not catch the error from the `parse()` method itself.

### Patches

The issue has been patched in version 0.8.2 by making the request parser catch `URI::InvalidURIError` and enter an error state if the `Host` header is malformed. This means the request is considered invalid and should not establish a WebSocket connection.

### Workarounds

No known workarounds exist.

### Acknowledgements

This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / websocket-driver
Introduced in: 0 Fixed in: 0.8.2
Fix bundle update websocket-driver

References