NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #55 most downloaded on npm
Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js
Last release 5 days ago
26 Sep 2026
Release timing varies
gaps range from 1 weeks to 8 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
189 releases · first in 2011
Nothing published for this version
Fixed a DoS vulnerability (f8fdcd4).
Removed istanbul coverage folder from npm package (fac50ac).
One column per quarter.
Added support for bufferutil@>1 and utf-8-validate@>2 (b4cf110).
bufferutil@>1 and utf-8-validate@>2 (b4cf110).The masking key is now generated using crypto.randomBytes() instead of Math.random() (#994).
crypto.randomBytes() instead of
Math.random() (#994).https://github.com/websockets/ws/compare/1.1.0...1.1.1
https://github.com/websockets/ws/compare/1.1.0...1.1.1
https://github.com/websockets/ws/compare/1.0.1...1.1.0
https://github.com/websockets/ws/compare/1.0.1...1.1.0
There has been vulnerability in the ping functionality of the ws module which allowed clients to allocate memory by simply sending a ping frame. The p…
There has been vulnerability in the ping functionality of the ws module which allowed clients to allocate memory by simply sending a ping frame. The ping functionality by default responds with a pong frame and the previously given payload of the ping frame. This is exactly what you expect, but internally we always transform all data that we need to send to a Buffer instance and this is where the problem was. We didn't do any checks for the type of data we were sending. With buffers in node when you allocate it when a number instead of a string it will allocate the amount of bytes.
var x = new Buffer(100);
// vs
var x = new Buffer('100');
This would allocate 100 bytes of memory in the first example and just 3 bytes with 100 as value in the second example. So when the server would receive a ping message of 1000 it would allocate 1000 bytes on the server and returned non-zeroed buffer to the client instead of the actual 100 message.
var ws = require('ws')
var server = new ws.Server({ port: 9000 })
var client = new ws('ws://localhost:9000')
client.on('open', function () {
console.log('open')
client.ping(50) // this makes the server return a non-zeroed buffer of 50 bytes
client.on('pong', function (data) {
console.log('got pong')
console.log(data) // a non-zeroed out allocated buffer returned from the server
})
})
As you can imagine that is pretty darn dangerous so we fixed it as soon as we received a heads up about this. So I would like to thank @feross and @mafintosh for discovering this vulnerability and disclosing it to me so it could be resolved asap.
Discontinued support for all node versions except for 0.12, 4.0 and 5.0. We should focus on the future and that will be Node 5 and ES6.
var WS = window.WebSocket || require('ws')So future.. Ideally I want to start rewriting parts of the library in ES6 and completely clean up the code base. Pull requests for this are encouraged and appreciated <3 as this takes a lot of time.
Nothing published for this version
Nothing published for this version
Nothing published for this version
The ws module have been plagued with build failures that was caused by it's optional compilation of binary add-ons. It used an installation hack inste
The ws module have been plagued with build failures that was caused by it's optional compilation of binary add-ons. It used an installation hack instead of using optionalDependencies for it. Now if optional dependencies work correctly.. There shouldn't be any more build failures because of the binary addon building failed.
And as you might have noticed, we moved the repository to a new organization: websockets this allows us to more easily onboard people, split up everything in to more tiny maintainable modules etc.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →