PT-2026-50456 · Npm+1 · Undici+1

·

CVE-2026-12151

·

Published

2026-06-17

·

Updated

2026-07-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions undici versions 6.17.0 through 6.25.x undici versions 7.0.0 through 7.27.x undici versions 8.0.0 through 8.4.x
Description The WebSocket client fails to limit the number of fragments in a message, only enforcing the maxPayloadSize on the cumulative byte count. A malicious server can send numerous small or empty continuation frames that bypass per-frame and cumulative-size validation, leading to unbounded memory growth, memory exhaustion, and a denial of service. This affects applications using the new WebSocket(...) client or the WebSocketStream API when connecting to a compromised or attacker-controlled endpoint.
Recommendations Upgrade to version 6.26.0 or later for the 6.x branch. Upgrade to version 7.28.0 or later for the 7.x branch. Upgrade to version 8.5.0 or later for the 8.x branch.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:35841
ALSA-2026:35842
ALSA-2026:35891
ALSA-2026:35892
ALSA-2026:39868
ALSA-2026:41947
CLEANSTART-2026-KN24948
CLEANSTART-2026-ZJ21676
CVE-2026-12151
ECHO-F2CE-9C62-59CE
GHSA-VXPW-J846-P89Q
OPENSUSE-SU-2026:11121-1
OPENSUSE-SU-2026:21058-1
OPENSUSE-SU-2026:21236-1
RHSA-2026:35841
RHSA-2026:35842
RHSA-2026:35891
RHSA-2026:35892
RHSA-2026:38009
RHSA-2026:39246
RHSA-2026:39868
SUSE-SU-2026:22368-1
SUSE-SU-2026:22565-1
SUSE-SU-2026:2633-1
SUSE-SU-2026:2647-1
SUSE-SU-2026:2695-1

Affected Products

Rocky Linux
Undici