CVE-2026-12151
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
17/06/2026
Last modified:
30/07/2026
Description
Impact:<br />
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.<br />
<br />
Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.<br />
<br />
All releases starting at undici 6.17.0 are affected.<br />
<br />
Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:<br />
No workaround is available. The fix must be applied through an upgrade.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | 6.17.0 (including) | 6.27.0 (excluding) |
| cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | 7.0.0 (including) | 7.28.0 (excluding) |
| cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | 8.0.0 (including) | 8.5.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://cna.openjsf.org/security-advisories.html
- https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q
- https://access.redhat.com/errata/RHSA-2026:34342
- https://access.redhat.com/errata/RHSA-2026:35841
- https://access.redhat.com/errata/RHSA-2026:35842
- https://access.redhat.com/errata/RHSA-2026:35891
- https://access.redhat.com/errata/RHSA-2026:35892
- https://access.redhat.com/errata/RHSA-2026:36621
- https://access.redhat.com/errata/RHSA-2026:36754
- https://access.redhat.com/errata/RHSA-2026:36820
- https://access.redhat.com/errata/RHSA-2026:38009
- https://access.redhat.com/errata/RHSA-2026:38236
- https://access.redhat.com/errata/RHSA-2026:39246
- https://access.redhat.com/errata/RHSA-2026:39868
- https://access.redhat.com/errata/RHSA-2026:41929
- https://access.redhat.com/errata/RHSA-2026:41947
- https://access.redhat.com/errata/RHSA-2026:48124
- https://access.redhat.com/errata/RHSA-2026:48151
- https://access.redhat.com/security/cve/CVE-2026-12151
- https://bugzilla.redhat.com/show_bug.cgi?id=2489980
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json



