PT-2026-25075 · Undici+1 · Undici+1
Matteo Collina
+1
·
Published
2026-03-12
·
Updated
2026-05-18
·
CVE-2026-1528
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
undici versions prior to 7.24.0
undici versions prior to 6.24.0
Description
A server can respond with a WebSocket frame utilizing the 64-bit length format and an excessively large length value. The
ByteParser component within undici experiences an integer overflow during internal mathematical operations, leading to an invalid state and ultimately causing a fatal TypeError that terminates the process.Recommendations
Upgrade to undici version 7.24.0 or later.
Upgrade to undici version 6.24.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rocky Linux
Undici