Skip to content

Releases: websockets/ws

7.5.11

Choose a tag to compare

@lpinca lpinca released this 22 May 18:03

Bug fixes

6.2.4

Choose a tag to compare

@lpinca lpinca released this 22 May 18:03

Bug fixes

5.2.5

Choose a tag to compare

@lpinca lpinca released this 22 May 18:02

Bug fixes

8.20.1

Choose a tag to compare

@lpinca lpinca released this 12 May 15:47

Bug fixes

  • Fixed an uninitialized memory disclosure issue in websocket.close()
    (c0327ec).

Providing a TypedArray (e.g. Float32Array) as the reason argument for
websocket.close(), rather than the supported string or Buffer types, caused
uninitialized memory to be disclosed to the remote peer.

import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebSocketServer(
  { port: 0, skipUTF8Validation: true },
  function () {
    const { port } = wss.address();
    const ws = new WebSocket(`ws://localhost:${port}`, {
      skipUTF8Validation: true
    });

    ws.on('close', function (code, reason) {
      deepStrictEqual(reason, Buffer.alloc(80));
    });
  }
);

wss.on('connection', function (ws) {
  ws.close(1000, new Float32Array(20));
});

The issue was privately reported by Nikita Skovoroda.

8.20.0

Choose a tag to compare

@lpinca lpinca released this 21 Mar 17:29

Features

  • Added exports for the PerMessageDeflate class and utilities for the
    Sec-WebSocket-Extensions and Sec-WebSocket-Protocol headers (d3503c1).

8.19.0

Choose a tag to compare

@lpinca lpinca released this 05 Jan 17:41

Features

  • Added the closeTimeout option (#2308).

Bug fixes

  • Handled a forthcoming breaking change in Node.js core (1998485).

8.18.3

Choose a tag to compare

@lpinca lpinca released this 28 Jun 13:26

Bug fixes

  • Fixed a spec violation where the Sec-WebSocket-Version header was not added
    to the HTTP response if the client requested version was either invalid or
    unacceptable (#2291).

8.18.2

Choose a tag to compare

@lpinca lpinca released this 02 May 19:03

Bug fixes

  • Fixed an issue that, during message decompression when the maximum size was
    exceeded, led to the emission of an inaccurate error and closure of the
    connection with an improper close code (#2285).

8.18.1

Choose a tag to compare

@lpinca lpinca released this 21 Feb 09:32

Bug fixes

  • The length of the UNIX domain socket paths in the tests has been shortened to
    make them work when run via CITGM (021f7b8).

8.18.0

Choose a tag to compare

@lpinca lpinca released this 03 Jul 16:39

Features

  • Added support for Blob (#2229).