DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-85024: CVE-2026-85024: Denial of Service via Uncaught Exception in undici WebSocket Client

CVE-2026-85024: Denial of Service via Uncaught Exception in undici WebSocket Client

Vulnerability ID: CVE-2026-85024
CVSS Score: 5.9
Published: 2026-09-28

A high-severity Denial of Service (DoS) vulnerability exists in the undici WebSocket client implementation when processing compressed frames. The vulnerability is caused by a race condition where event listeners, including error handlers, are stripped from the active zlib stream during cleanup before the stream is fully terminated, leading to an unhandled exception.

TL;DR

A race condition in undici's permessage-deflate cleanup allows remote servers to crash Node.js applications by sending an over-limit payload followed by trailing malformed bytes, triggering an uncaught exception.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-248 (Uncaught Exception)
  • Attack Vector: Network
  • CVSS v3.1 Score: 5.9 (Medium)
  • EPSS Score: 0.00412
  • Exploit Status: Proof of Concept Available
  • KEV Status: Not Listed

Affected Systems

  • undici packages using WebSockets with permessage-deflate enabled
  • Node.js instances using undici as native HTTP/WebSocket client
  • undici: >= 6.25.0, < 6.28.1 (Fixed in: 6.28.1)
  • undici: >= 7.28.0, < 7.29.1 (Fixed in: 7.29.1)
  • undici: >= 8.1.0, < 8.10.2 (Fixed in: 8.10.2)

Code Analysis

Commit: 4411a23

Fix: destroy inflate stream when size limit is exceeded (v6 branch)

Commit: 07c60d9

Fix: destroy inflate stream when size limit is exceeded (v7 branch)

Commit: 63cf698

Fix: destroy inflate stream when size limit is exceeded (v8 branch)

Mitigation Strategies

  • Upgrade the undici package to fixed version branches (v6.28.1, v7.29.1, or v8.10.2).
  • Use package overrides or resolutions to force secure transitives.
  • Disable the permessage-deflate extension during client-side WebSocket negotiation.

Remediation Steps:

  1. Identify vulnerable occurrences of undici using npm ls undici.
  2. Modify package.json to override transitive references or directly run npm update undici.
  3. If deploying via Node.js system dependencies, upgrade the Node.js runtime binary to the latest LTS patch release.
  4. Deploy code changes and verify dependency resolutions using automated dependency scanners.

References


Read the full report for CVE-2026-85024 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)