An integer overflow vulnerability exists in the WebSocket...
High severity
Unreviewed
Published
Sep 29, 2025
to the GitHub Advisory Database
•
Updated Sep 30, 2025
Description
Published by the National Vulnerability Database
Sep 29, 2025
Published to the GitHub Advisory Database
Sep 29, 2025
Last updated
Sep 30, 2025
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.
References