Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f269-vfmq-vjvj

Опубликовано: 13 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

Impact

A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.

Patches

Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

Workarounds

There are no workarounds.

Пакеты

Наименование

undici

npm
Затронутые версииВерсия исправления

>= 6.0.0, < 6.24.0

6.24.0

Наименование

undici

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 7.24.0

7.24.0

EPSS

Процентиль: 39%
0.00488
Низкий

7.5 High

CVSS3

Дефекты

CWE-1284
CWE-248

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

CVSS3: 7.5
redhat
5 месяцев назад

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

CVSS3: 7.5
nvd
5 месяцев назад

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

CVSS3: 7.5
debian
5 месяцев назад

ImpactA server can reply with a WebSocket frame using the 64-bit lengt ...

rocky
4 месяца назад

Important: nodejs:22 security update

EPSS

Процентиль: 39%
0.00488
Низкий

7.5 High

CVSS3

Дефекты

CWE-1284
CWE-248