CVE-2026-12151

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*

History

30 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:48124 -
  • () https://access.redhat.com/errata/RHSA-2026:48151 -

21 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:41929 -
  • () https://access.redhat.com/errata/RHSA-2026:41947 -

16 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36621 -
  • () https://access.redhat.com/errata/RHSA-2026:38236 -
  • () https://access.redhat.com/errata/RHSA-2026:39868 -

15 Jul 2026, 12:17

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2026:38236', 'source': '0b0ca135-0b70-47e7-9f44-1890c2a1c46c'}

15 Jul 2026, 02:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:39246 -

13 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:38009 -
  • () https://access.redhat.com/errata/RHSA-2026:38236 -

09 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36754 -
  • () https://access.redhat.com/errata/RHSA-2026:36820 -

07 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:35891 -
  • () https://access.redhat.com/errata/RHSA-2026:35892 -

06 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:35841 -
  • () https://access.redhat.com/errata/RHSA-2026:35842 -

02 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:34342 -

30 Jun 2026, 03:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-12151 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2489980 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json -

25 Jun 2026, 17:47

Type Values Removed Values Added
CPE cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
References () https://cna.openjsf.org/security-advisories.html - () https://cna.openjsf.org/security-advisories.html - Vendor Advisory
References () https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q - () https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q - Vendor Advisory
First Time Nodejs
Nodejs undici

17 Jun 2026, 20:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 17:16

Updated : 2026-07-30 12:17


NVD link : CVE-2026-12151

Mitre link : CVE-2026-12151

CVE.ORG link : CVE-2026-12151


JSON object : View

Products Affected

nodejs

  • undici
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling