Intel

AIKIDO-2026-145478

undici is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-12151 Published Jun 22, 2026

75

High Risk

This Affects:

JSundici
6.17.0 - 6.25.0
Fixed in 6.26.0
7.0.0 - 7.27.2
Fixed in 7.28.0
8.0.0 - 8.4.1
Fixed in 8.5.0
Are you affected? Scan for Free

TL;DR

undici's WebSocket client enforces the maxPayloadSize limit on the cumulative byte size of a fragmented message but never limits the number of fragments. A malicious or compromised WebSocket server can stream a very large number of small or empty continuation frames that each pass per-frame and cumulative-size checks while collectively driving unbounded memory growth in the client. An application that connects its WebSocket or WebSocketStream client to an attacker-controlled endpoint can be driven to memory exhaustion and denial of service. The fix adds a limit on the number of accepted fragments so a message cannot grow without bound.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

undici is vulnerable to Denial of Service (DoS) in versions 6.17.0 - 6.25.0, 7.0.0 - 7.27.2 and 8.0.0 - 8.4.1.

How to fix this

Upgrade the undici library to the patch version.

Links

Other

cna.openjsf.org/security-advisories.html
https://cna.openjsf.org/security-advisories.html
access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:34342
access.redhat.com/errata/RHSA-2026:35841
https://access.redhat.com/errata/RHSA-2026:35841
access.redhat.com/errata/RHSA-2026:35842
https://access.redhat.com/errata/RHSA-2026:35842
access.redhat.com/errata/RHSA-2026:35891
https://access.redhat.com/errata/RHSA-2026:35891
access.redhat.com/errata/RHSA-2026:35892
https://access.redhat.com/errata/RHSA-2026:35892
access.redhat.com/errata/RHSA-2026:36621
https://access.redhat.com/errata/RHSA-2026:36621
access.redhat.com/errata/RHSA-2026:36754
https://access.redhat.com/errata/RHSA-2026:36754
access.redhat.com/errata/RHSA-2026:36820
https://access.redhat.com/errata/RHSA-2026:36820
access.redhat.com/errata/RHSA-2026:38009
https://access.redhat.com/errata/RHSA-2026:38009
access.redhat.com/errata/RHSA-2026:38236
https://access.redhat.com/errata/RHSA-2026:38236
access.redhat.com/errata/RHSA-2026:39246
https://access.redhat.com/errata/RHSA-2026:39246
access.redhat.com/errata/RHSA-2026:39868
https://access.redhat.com/errata/RHSA-2026:39868
access.redhat.com/errata/RHSA-2026:41929
https://access.redhat.com/errata/RHSA-2026:41929
access.redhat.com/errata/RHSA-2026:41947
https://access.redhat.com/errata/RHSA-2026:41947
access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:47728
access.redhat.com/errata/RHSA-2026:48124
https://access.redhat.com/errata/RHSA-2026:48124
access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:48151
access.redhat.com/security/cve/CVE-2026-12151
https://access.redhat.com/security/cve/CVE-2026-12151
bugzilla.redhat.com/show_bug.cgi?id=2489980
https://bugzilla.redhat.com/show_bug.cgi?id=2489980
security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json