← Vulnerability feed

Vulnerability record · CVE-2026-12151 · published 17 June 2026

CVE-2026-12151: Nodejs undici uncontrolled resource consumption vulnerability

Nodejs · Undici

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.

7.5 CVSS 3.1 High EPSS 0.79% · top 45.6% CWE-400 · Uncontrolled resource consumptionCWE-770 · Allocation without limits
7.5CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
31References
11 Sep 2026Last modified by NVD

Description

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cna.openjsf.org/security-advisories.html Vendor Advisory
https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:35841
https://access.redhat.com/errata/RHSA-2026:35842
https://access.redhat.com/errata/RHSA-2026:35891
https://access.redhat.com/errata/RHSA-2026:35892
https://access.redhat.com/errata/RHSA-2026:36621
https://access.redhat.com/errata/RHSA-2026:36754
https://access.redhat.com/errata/RHSA-2026:36820
https://access.redhat.com/errata/RHSA-2026:38009
https://access.redhat.com/errata/RHSA-2026:38236
https://access.redhat.com/errata/RHSA-2026:39246
https://access.redhat.com/errata/RHSA-2026:39868
https://access.redhat.com/errata/RHSA-2026:41929
https://access.redhat.com/errata/RHSA-2026:41947
https://access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:48124
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:52399
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:62260
https://access.redhat.com/errata/RHSA-2026:65126
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/errata/RHSA-2026:66545
https://access.redhat.com/security/cve/CVE-2026-12151
https://bugzilla.redhat.com/show_bug.cgi?id=2489980
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json

Track CVE-2026-12151 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-1525Nodejs undici http request smuggling vulnerabilityUndici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-leng…EPSS 0.49%9.8CVE-2022-35949Nodejs undici server-side request forgery (ssrf) vulnerabilityundici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes…EPSS 1.8%9.1CVE-2026-84961Nodejs undici improper certificate validation vulnerabilityundici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Bec…EPSS 0.25%9.1CVE-2026-13697Nodejs undici information exposure vulnerabilityundici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…EPSS 0.57%8.8CVE-2026-6734Nodejs undici origin validation error vulnerabilityImpact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches…EPSS 0.39%8.2CVE-2026-84933Nodejs undici information exposure vulnerabilityundici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that …EPSS 0.34%7.5CVE-2026-19534Nodejs undici unchecked return value vulnerabilityundici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client ne…EPSS 0.39%7.5CVE-2026-85014Nodejs undici vulnerabilityundici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close…EPSS 0.54%

Source: NIST National Vulnerability Database (record CVE-2026-12151), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.