Severity
Details
- CVSS score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE ID
Overview
About vulnerability
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.
Affected applications are those using the undici WebSocket client (new WebSocket(…)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.
All releases starting at undici 6.17.0 are affected.
Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
Details
- Affected product:
- AlmaLinux 9.2 ESU , AngularJS , Node.js , Protocol Buffers , React , TuxCare 9.6 ESU , Vue , api-extractor-model , astro , babel-loader , browser-sync , chrome-launcher , chromium-edge-launcher , cli , css-loader , css-minimizer-webpack-plugin , definitelytyped , del , dev-middleware , engine.io , esbuild-loader , extract-css-chunks-webpack-plugin , facebook/jest , facebook/metro , file-loader , file-system-cache , fork-ts-checker-webpack-plugin , friendly-errors-webpack-plugin , globby , got , happy-dom , hard-source-webpack-plugin , html-webpack-plugin , http-proxy-middleware , inquirer-external-editor , inquirer.js , jest , karma , karma-jasmine , karma-junit-reporter , karma-requirejs , metro , mini-css-extract-plugin , miniflare , minimizer-webpack-plugin , mongodb , mongodb-connection-string-url , mongoose , nguniversal , nuxt , parse5 , plugins , postcss-loader , pretty-format , remix , rollup , rollup-plugin-node-resolve , rollup-plugin-sourcemaps , rules_nodejs , rushstack , selfsigned , socket.io , sort-package-json , storybook , strong-error-handler , style-resources-loader , thread-loader , time-fix-plugin , ts-command-line , undici , url-loader , vanilla-extract , vite , vite-node , webpack , webpack-dev-middleware , webpack-dev-server , webpackbar , worker-loader , workers-sdk , xdm
- Affected packages:
- miniflare @ 3.20250718.3 (+816 more)