Please report security vulnerabilities privately via GitHub Private Vulnerability Reporting. Feedback is generally provided within 72 hours. If no response is received within that time frame, please follow up directly with the maintainers. Email addresses for the lead developers can be found in the git commit history, for example, by running the following command:
git --no-pager show -s --format='%an <%ae>' <gitsha>
where <gitsha> is the SHA of their latest commit in the project.
Once the report is acknowledged and the vulnerability is confirmed, a fix will be developed in collaboration with the reporter and a public security advisory published on GitHub Security Advisories.
- 04 Jan 2016: Buffer vulnerability
- 08 Nov 2017:
DoS in the
Sec-Websocket-Extensionsheader parser - 25 May 2021:
ReDoS in
Sec-Websocket-Protocolheader - 16 Jun 2024: DoS when handling a request with many HTTP headers
- 12 May 2026:
Uninitialized memory disclosure in
websocket.close() - 22 May 2026: Memory exhaustion DoS from tiny fragments and data chunks