Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-61666PATCHED
rubygems · websocket-driver

websocket-driver: Denial of service via malformed Host header

Description

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.

Affected Products

VendorProductVersions
rubygemswebsocket-driver< 0.8.2

References

  • https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-2x63-gw47-w4mm(x_refsource_CONFIRM)
  • https://github.com/faye/websocket-driver-ruby/commit/7d6fd87759a2fdc83590d3b49ffa661dc53fa128(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB6d ago
CVE-2026-61666 | Faye websocket-driver-ruby up to 0.8.1 HTTP Request request.rb WebSocket::Driver.server input validation
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
websocket-driver@0.8.2
CWECWE-248
PublishedJul 21, 2026
Tags
GHSA-2x63-gw47-w4mmrubygems
Trending Score8
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 60
HIGHCVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Trending: 7
NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 6
HIGHCVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
Trending: 5
MEDIUMCVE-2026-45415
Decidim: CSV census record endpoints improper authorization
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Patch Available
Aug 17, 2026