CVE-2026-12151

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
References
Link Resource
https://cna.openjsf.org/security-advisories.html Vendor Advisory
https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:35841
https://access.redhat.com/errata/RHSA-2026:35842
https://access.redhat.com/errata/RHSA-2026:35891
https://access.redhat.com/errata/RHSA-2026:35892
https://access.redhat.com/errata/RHSA-2026:36621
https://access.redhat.com/errata/RHSA-2026:36754
https://access.redhat.com/errata/RHSA-2026:36820
https://access.redhat.com/errata/RHSA-2026:38009
https://access.redhat.com/errata/RHSA-2026:38236
https://access.redhat.com/errata/RHSA-2026:39246
https://access.redhat.com/errata/RHSA-2026:39868
https://access.redhat.com/errata/RHSA-2026:41929
https://access.redhat.com/errata/RHSA-2026:41947
https://access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:48124
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:52399
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:62260
https://access.redhat.com/errata/RHSA-2026:65126
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/errata/RHSA-2026:66545
https://access.redhat.com/security/cve/CVE-2026-12151
https://bugzilla.redhat.com/show_bug.cgi?id=2489980
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-06-17 17:16

Updated : 2026-09-11 13:17


NVD link : CVE-2026-12151

Mitre link : CVE-2026-12151

CVE.ORG link : CVE-2026-12151


JSON object : View

Products Affected

nodejs

  • undici
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling