CVE-2026-1528
HIGHundici 6.0.0-6.23.9 7.0.0-7.23.9 - Denial of Service via WebSocket Frame Length Overflow
Title source: llmDescription
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
References (21)
Core 21
Core References
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:13826
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:17789
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:21772
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:21931
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:5807
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7080
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7123
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7302
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7310
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7350
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7670
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7675
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7983
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:9742
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-1528
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2447145
Third Party Advisory
https://hackerone.com/reports/3537648
Various Sources
https://cna.openjsf.org/security-advisories.html
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:34342
Scores
CVSS v3
7.5
EPSS
0.0049
EPSS Percentile
39.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1284
CWE-248
Status
published
Products (4)
nodejs/undici
< 6.24.0
npm/undici
6.0.0 - 6.24.0npm
undici/undici
6.24.0: 7.24.0
undici/undici
>= 6.0.0 < 6.24.0; 7.0.0 < 7.24.0
Published
Mar 12, 2026
Tracked Since
Mar 13, 2026