CVE-2026-2577: Websocketserver Missing Localhost Binding

WebSocketServer is instantiated without an explicit `host` parameter. The `ws` library defaults to 0.0.0.0 (all network interfaces) when `host` is omitted, exposing the server to any remote attacker with network access to the port. Set `host: '127.0.0.1'` to restrict to localhost unless external access is explicitly intended and separately protected by authe

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-2577-websocketserver-missing-localhost-binding --engine opengrep

Description

WebSocketServer is instantiated without an explicit `host` parameter. The `ws` library defaults to 0.0.0.0 (all network interfaces) when `host` is omitted, exposing the server to any remote attacker with network access to the port. Set `host: '127.0.0.1'` to restrict to localhost unless external access is explicitly intended and separately protected by authe