[Git][security-tracker-team/security-tracker][master] Add new websocket-driver issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 18 13:22:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eff1a086 by Salvatore Bonaccorso at 2026-07-18T14:22:15+02:00
Add new websocket-driver issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57,15 +57,25 @@ CVE-2026-54498 (view_component is a framework for building reusable, testable, a
 CVE-2026-54497 (view_component is a framework for building reusable, testable, and enc ...)
 	NOT-FOR-US: view_component framework
 CVE-2026-54490 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
-	TODO: check
+	- node-websocket-driver <unfixed>
+	NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-mp7j-qc5w-4988
+	NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/c55679a5b18251dd0a55d18a0cc6a4fd8822b92f (0.7.5)
 CVE-2026-54466 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
-	TODO: check
+	- node-websocket-driver <unfixed>
+	NOTE: https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6
+	NOTE: Fixed by: https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680 (0.7.5)
 CVE-2026-54465 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
-	TODO: check
+	- ruby-websocket-driver 0.8.1-1
+	NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw
+	NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/17b569f232896e71d458404ccf4854f80e987710 (0.8.1)
 CVE-2026-54464 (### Impact  If this library is used in tandem with the `permessage-def ...)
-	TODO: check
+	- ruby-websocket-driver 0.8.1-1
+	NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-33ph-fccm-39pj
+	NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/fa8641724f10bf3273585f1dcf9041f540bbd036 (0.8.1)
 CVE-2026-54463 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
-	TODO: check
+	- ruby-websocket-driver 0.8.1-1
+	NOTE: https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p
+	NOTE: Fixed by: https://github.com/faye/websocket-driver-ruby/commit/d0141f041f6e3677a951255d547a313e732ccbe0 (0.8.1)
 CVE-2026-54335 (Feathersjs is a framework for creating web APIs and real-time applicat ...)
 	NOT-FOR-US: Feathersjs
 CVE-2026-54244 (Statamic is a Laravel and Git powered content management system (CMS). ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff1a08664d338ec86dcb09572dc8f342a9fd680

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff1a08664d338ec86dcb09572dc8f342a9fd680
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260718/263973f5/attachment.htm>


More information about the debian-security-tracker-commits mailing list