Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f269-vfmq-vjvj

Опубликовано: 13 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

Impact

A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.

Patches

Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

Workarounds

There are no workarounds.

Пакеты

Наименование

undici

npm
Затронутые версииВерсия исправления

>= 6.0.0, < 6.24.0

6.24.0

Наименование

undici

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 7.24.0

7.24.0

EPSS

Процентиль: 32%
0.00128
Низкий

7.5 High

CVSS3

Дефекты

CWE-1284
CWE-248

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

CVSS3: 7.5
redhat
18 дней назад

A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici's ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.

CVSS3: 7.5
nvd
18 дней назад

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

CVSS3: 7.5
debian
18 дней назад

ImpactA server can reply with a WebSocket frame using the 64-bit lengt ...

EPSS

Процентиль: 32%
0.00128
Низкий

7.5 High

CVSS3

Дефекты

CWE-1284
CWE-248