Количество 17
Количество 17
CVE-2026-1526
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.
CVE-2026-1526
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.
CVE-2026-1526
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.
CVE-2026-1526
The undici WebSocket client is vulnerable to a denial-of-service attac ...
GHSA-vrm6-8vpv-qv8q
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
RLSA-2026:7302
Important: nodejs:22 security update
RLSA-2026:7123
Important: nodejs:22 security update
RLSA-2026:7080
Important: nodejs22 security update
ELSA-2026-7302
ELSA-2026-7302: nodejs:22 security update (IMPORTANT)
ELSA-2026-7123
ELSA-2026-7123: nodejs:22 security update (IMPORTANT)
ELSA-2026-7080
ELSA-2026-7080: nodejs22 security update (IMPORTANT)
RLSA-2026:7670
Important: nodejs:24 security update
ELSA-2026-7670
ELSA-2026-7670: nodejs:24 security update (IMPORTANT)
RLSA-2026:7675
Important: nodejs24 security update
RLSA-2026:7350
Important: nodejs:24 security update
ELSA-2026-7675
ELSA-2026-7675: nodejs24 security update (IMPORTANT)
ELSA-2026-7350
ELSA-2026-7350: nodejs:24 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-1526 The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-1526 The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-1526 The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-1526 The undici WebSocket client is vulnerable to a denial-of-service attac ... | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
GHSA-vrm6-8vpv-qv8q Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
RLSA-2026:7302 Important: nodejs:22 security update | 4 месяца назад | |||
RLSA-2026:7123 Important: nodejs:22 security update | 4 месяца назад | |||
RLSA-2026:7080 Important: nodejs22 security update | 4 месяца назад | |||
ELSA-2026-7302 ELSA-2026-7302: nodejs:22 security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-7123 ELSA-2026-7123: nodejs:22 security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-7080 ELSA-2026-7080: nodejs22 security update (IMPORTANT) | 4 месяца назад | |||
RLSA-2026:7670 Important: nodejs:24 security update | 4 месяца назад | |||
ELSA-2026-7670 ELSA-2026-7670: nodejs:24 security update (IMPORTANT) | 4 месяца назад | |||
RLSA-2026:7675 Important: nodejs24 security update | 4 месяца назад | |||
RLSA-2026:7350 Important: nodejs:24 security update | 4 месяца назад | |||
ELSA-2026-7675 ELSA-2026-7675: nodejs24 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-7350 ELSA-2026-7350: nodejs:24 security update (IMPORTANT) | 4 месяца назад |
Уязвимостей на страницу