Description
undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
Published: 2026-09-04
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs when the WebSocket client uses the permessage-deflate extension and the internal zlib inflate stream removes its error listener during size‑limit cleanup. A malicious remote peer can then send a compressed frame that expands beyond the 128 MiB decompression threshold and includes a malformed DEFLATE byte. The inflate stream produces a data error but, because the error listener has been removed, Node.js treats the event as an unhandled exception and terminates the entire process, resulting in a denial of service. The flaw corresponds to CWE‑248 and CWE‑431, representing unhandled exceptions and improper handling of input sizes.

Affected Systems

Affected products are the undici library for Node.js. The issue exists in versions 6.25.0 through 6.28.1, 7.28.0 through 7.29.1, and 8.1.0 through 8.10.2. Users should upgrade to the latest patched releases 6.28.1, 7.29.1, or 8.10.2 to eliminate the flaw.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity level. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not known to be actively exploited. Nevertheless, the exploit is remote, unauthenticated, and requires no specific application configuration besides the WebSocket connection. An attacker can send a crafted payload of roughly 130 KB that decompresses past the built‑in limit, triggering a crash. Because the crash terminates the process, repeated attempts can be made, making the threat asymmetric. This kind of weakness is represented by CWE‑248 and CWE‑431. The overall risk remains moderate: significant impact with limited exploitation probability in the absence of a specific target.

Generated by OpenCVE AI on September 5, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade undici to version 6.28.1, 7.29.1, or 8.10.2.
  • If upgrading is not feasible, disable the permessage-deflate compression on the server side or configure the peer to reject messages that exceed the decompression size limit.
  • Deploy a process manager or service restart mechanism to automatically recover from crashes caused by the denial of service.

Generated by OpenCVE AI on September 5, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Undici
Undici undici
Vendors & Products Undici
Undici undici

Sat, 05 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-431
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 04 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
Title undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-04T19:30:54.293Z

Reserved: 2026-09-02T19:57:23.011Z

Link: CVE-2026-85024

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T17:17:02.590

Modified: 2026-09-04T20:17:31.137

Link: CVE-2026-85024

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-04T16:20:34Z

Links: CVE-2026-85024 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T01:30:17Z

Weaknesses