CVE-2016-10542 affects the Node.js ws WebSocket library in version 1.1.0 and earlier. The vulnerability can be triggered by sending an overly long WebSocket payload to a ws server, causing the Node.js process handling the connection to crash. Based on the provided information, the issue is a denial-of-service condition caused by insufficient handling of excessively large input in WebSocket frames.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
ws server. This can interrupt availability of any application or service that depends on that process to handle WebSocket connections.If you can’t patch tonight, do this now.
ws services to trusted clients, place the service behind controls that enforce request and frame size limits where possible, and monitor for malformed or unusually large WebSocket payloads. Process supervision and automatic restart can reduce downtime but do not remediate the underlying flaw.Patch, then assume compromise.
ws package to a version newer than 1.1.0 that is not affected by CVE-2016-10542. If direct upgrade guidance is managed through package-locking or dependency constraints, ensure all transitive dependencies also resolve to a fixed version.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module (modules/auxiliary/dos/http/ws_dos.rb) that exploits a denial of service vulnerability (CVE-2016-10542) in the 'ws' npm module for Node.js. The exploit works by sending a specially crafted WebSocket upgrade HTTP request with the 'Sec-WebSocket-Extensions: constructor' header to the target service. If the target is running a vulnerable version of 'ws', this request will crash the component, resulting in a denial of service. The module allows the user to specify the target port (default 3000) and base path (default '/'). The attack vector is network-based, requiring TCP connectivity to the target's WebSocket service. The code is written in Ruby and is designed to be run within the Metasploit framework. The repository is operational in maturity, providing a working exploit for the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.