CVE-2026-1528
HIGHundici 6.0.0-6.23.9 7.0.0-7.23.9 - Denial of Service via WebSocket Frame Length Overflow
Title source: llmDescription
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
References (3)
Core 3
Core References
Various Sources
https://cna.openjsf.org/security-advisories.html
Third Party Advisory
https://hackerone.com/reports/3537648
Scores
CVSS v3
7.5
EPSS
0.0034
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-248
CWE-1284
Status
published
Products (4)
nodejs/undici
< 6.24.0
npm/undici
6.0.0 - 6.24.0npm
undici/undici
6.24.0: 7.24.0
undici/undici
>= 6.0.0 < 6.24.0; 7.0.0 < 7.24.0
Published
Mar 12, 2026
Tracked Since
Mar 13, 2026