Количество 20
Количество 20
GHSA-vxpw-j846-p89q
undici WebSocket client vulnerable to denial of service via fragment count bypass
CVE-2026-12151
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
CVE-2026-12151
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
CVE-2026-12151
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
CVE-2026-12151
Impact: The undici WebSocket client enforces maxPayloadSize on the cum ...
RLSA-2026:41947
Important: nodejs:22 security, bug fix, and enhancement update
RLSA-2026:35892
Important: nodejs:22 security, bug fix, and enhancement update
RLSA-2026:35842
Important: nodejs22 security, bug fix, and enhancement update
ELSA-2026-41947
ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-35892
ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:39868
Important: nodejs:24 security, bug fix, and enhancement update
RLSA-2026:35891
Important: nodejs:24 security, bug fix, and enhancement update
RLSA-2026:35841
Important: nodejs24 security, bug fix, and enhancement update
ELSA-2026-39868
ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-35891
ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:2695-1
Security update for nodejs22
SUSE-SU-2026:2647-1
Security update for nodejs22
openSUSE-SU-2026:21236-1
Security update for nodejs24
SUSE-SU-2026:2633-1
Security update for nodejs24
openSUSE-SU-2026:21058-1
Security update for nodejs22
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-vxpw-j846-p89q undici WebSocket client vulnerable to denial of service via fragment count bypass | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade. | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade. | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade. | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cum ... | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
RLSA-2026:41947 Important: nodejs:22 security, bug fix, and enhancement update | 10 дней назад | |||
RLSA-2026:35892 Important: nodejs:22 security, bug fix, and enhancement update | 24 дня назад | |||
RLSA-2026:35842 Important: nodejs22 security, bug fix, and enhancement update | 23 дня назад | |||
ELSA-2026-41947 ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT) | 10 дней назад | |||
ELSA-2026-35892 ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT) | 23 дня назад | |||
RLSA-2026:39868 Important: nodejs:24 security, bug fix, and enhancement update | 15 дней назад | |||
RLSA-2026:35891 Important: nodejs:24 security, bug fix, and enhancement update | 24 дня назад | |||
RLSA-2026:35841 Important: nodejs24 security, bug fix, and enhancement update | 21 день назад | |||
ELSA-2026-39868 ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT) | 11 дней назад | |||
ELSA-2026-35891 ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT) | 24 дня назад | |||
SUSE-SU-2026:2695-1 Security update for nodejs22 | около 1 месяца назад | |||
SUSE-SU-2026:2647-1 Security update for nodejs22 | около 1 месяца назад | |||
openSUSE-SU-2026:21236-1 Security update for nodejs24 | 24 дня назад | |||
SUSE-SU-2026:2633-1 Security update for nodejs24 | около 1 месяца назад | |||
openSUSE-SU-2026:21058-1 Security update for nodejs22 | около 1 месяца назад |
Уязвимостей на страницу