CVE-2026-12151

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
17/06/2026
Last modified:
30/07/2026

Description

Impact:<br /> The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.<br /> <br /> Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.<br /> <br /> All releases starting at undici 6.17.0 are affected.<br /> <br /> Patches: Upgrade to undici &gt;= 6.26.0, &gt;= 7.28.0, or &gt;= 8.5.0. Workarounds:<br /> No workaround is available. The fix must be applied through an upgrade.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 6.17.0 (including) 6.27.0 (excluding)
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 7.0.0 (including) 7.28.0 (excluding)
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 8.0.0 (including) 8.5.0 (excluding)