Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-84890

Опубликовано: 04 сент. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration option to limit it. A malicious or faulty upstream can therefore return a small compressed payload, a compression bomb, that expands to hundreds of megabytes or more in client memory, an asymmetric resource consumption that can exhaust memory and crash the process. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
Версия от 7.15.0 (включая) до 7.29.1 (исключая)
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
Версия от 8.0.0 (включая) до 8.10.2 (исключая)

EPSS

Процентиль: 16%
0.0025
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.9
ubuntu
9 дней назад

(undici's decompress interceptor decompresses response bodies according ...)

CVSS3: 5.9
redhat
12 дней назад

undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration option to limit it. A malicious or faulty upstream can therefore return a small compressed payload, a compression bomb, that expands to hundreds of megabytes or more in client memory, an asymmetric resource consumption that can exhaust memory and crash the process. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

CVSS3: 5.9
debian
12 дней назад

undici's decompress interceptor decompresses response bodies according ...

EPSS

Процентиль: 16%
0.0025
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-770
Уязвимость CVE-2026-84890