You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

npm安装hitbtc-api后遇ws包DoS漏洞,寻求解决方案

Fixing High Severity DoS Vulnerability in hitbtc-api-node's ws Dependency

Let's walk through how to resolve this high-severity Denial of Service (DoS) vulnerability in the ws package that's a nested dependency of hitbtc-api-node.

Quick Fix Options

Option 1: Use npm's Built-in Audit Fix

First, try the simplest approach to let npm automatically patch the vulnerable dependency:

npm audit fix

This will attempt to upgrade ws to the minimum safe version (>=3.3.1) if the dependency constraints of hitbtc-api-node allow it.

Option 2: Force Resolution (If Automatic Fix Fails)

If npm audit fix doesn't work (because hitbtc-api-node might have a locked version range for ws), use npm-force-resolutions to override the nested dependency version:

  1. Install the resolution tool as a dev dependency:
    npm install --save-dev npm-force-resolutions
    
  2. Add a resolutions field to your package.json to enforce the safe ws version:
    "resolutions": {
      "ws": "^3.3.1"
    }
    
  3. Add a preinstall script to your package.json to run the resolution before installing dependencies:
    "scripts": {
      "preinstall": "npx npm-force-resolutions"
    }
    
  4. Reinstall your dependencies to apply the fix:
    npm install
    

Vulnerability Details

Overview

The vulnerable versions of ws will crash when receiving a malicious Sec-WebSocket-Extensions request header that uses Object.prototype property names (like constructor) as extension or parameter names.

Proof of Concept Code

Here's the test code that demonstrates the crash:

const WebSocket = require('ws');
const net = require('net');

const wss = new WebSocket.Server({ port: 3000 }, function () {
  const payload = 'constructor'; // or ',;constructor'
  const request = [
    'GET / HTTP/1.1',
    'Connection: Upgrade',
    'Sec-WebSocket-Key: test',
    'Sec-WebSocket-Version: 8',
    `Sec-WebSocket-Extensions: ${payload}`,
    'Upgrade: websocket',
    ''
  ].join('\n');

  const socket = net.connect(3000, function () {
    socket.resume();
    socket.write(request);
  });
});

Root Cause & Fix

The issue stems from improper handling of prototype pollution in the header parsing logic of older ws versions. Upgrading ws to version 3.3.1 or higher patches this parsing flaw, preventing the crash from malicious requests.

内容的提问来源于stack exchange,提问作者Irfan Muhammad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:10:45