PT-2026-50456 · Npm+1 · Undici+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
undici versions 6.17.0 through 6.25.x
undici versions 7.0.0 through 7.27.x
undici versions 8.0.0 through 8.4.x
Description
The WebSocket client fails to limit the number of fragments in a message, only enforcing the
maxPayloadSize on the cumulative byte count. A malicious server can send numerous small or empty continuation frames that bypass per-frame and cumulative-size validation, leading to unbounded memory growth, memory exhaustion, and a denial of service. This affects applications using the new WebSocket(...) client or the WebSocketStream API when connecting to a compromised or attacker-controlled endpoint.Recommendations
Upgrade to version 6.26.0 or later for the 6.x branch.
Upgrade to version 7.28.0 or later for the 7.x branch.
Upgrade to version 8.5.0 or later for the 8.x branch.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rocky Linux
Undici