Description
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Scores
CVSS v3
7.5
EPSS
0.0014
EPSS Percentile
33.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-248
CWE-1284
Status
published
Products (4)
nodejs/undici
< 6.24.0
npm/undici
6.0.0 - 6.24.0npm
undici/undici
6.24.0: 7.24.0
undici/undici
>= 6.0.0 < 6.24.0; 7.0.0 < 7.24.0
Published
Mar 12, 2026
Tracked Since
Mar 13, 2026