# CVE-2026-54466

## Summary

- **CVE ID:** CVE-2026-54466
- **Severity:** CRITICAL
- **CVSS Score:** 9.2 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N)
- **CWE:** CWE-130
- **Published:** Jul 17, 2026
- **Last Modified:** Jul 20, 2026

## Description

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.

## Affected Products

- faye — websocket-driver-node (< 0.7.5)

## References

- [CNA](https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6)
- [CNA](https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._