CVE-2026-85024: Denial of Service via Uncaught Exception in undici WebSocket Client
Vulnerability ID: CVE-2026-85024
CVSS Score: 5.9
Published: 2026-09-28
A high-severity Denial of Service (DoS) vulnerability exists in the undici WebSocket client implementation when processing compressed frames. The vulnerability is caused by a race condition where event listeners, including error handlers, are stripped from the active zlib stream during cleanup before the stream is fully terminated, leading to an unhandled exception.
TL;DR
A race condition in undici's permessage-deflate cleanup allows remote servers to crash Node.js applications by sending an over-limit payload followed by trailing malformed bytes, triggering an uncaught exception.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-248 (Uncaught Exception)
- Attack Vector: Network
- CVSS v3.1 Score: 5.9 (Medium)
- EPSS Score: 0.00412
- Exploit Status: Proof of Concept Available
- KEV Status: Not Listed
Affected Systems
- undici packages using WebSockets with permessage-deflate enabled
- Node.js instances using undici as native HTTP/WebSocket client
-
undici: >= 6.25.0, < 6.28.1 (Fixed in:
6.28.1) -
undici: >= 7.28.0, < 7.29.1 (Fixed in:
7.29.1) -
undici: >= 8.1.0, < 8.10.2 (Fixed in:
8.10.2)
Code Analysis
Commit: 4411a23
Fix: destroy inflate stream when size limit is exceeded (v6 branch)
Commit: 07c60d9
Fix: destroy inflate stream when size limit is exceeded (v7 branch)
Commit: 63cf698
Fix: destroy inflate stream when size limit is exceeded (v8 branch)
Mitigation Strategies
- Upgrade the undici package to fixed version branches (v6.28.1, v7.29.1, or v8.10.2).
- Use package overrides or resolutions to force secure transitives.
- Disable the permessage-deflate extension during client-side WebSocket negotiation.
Remediation Steps:
- Identify vulnerable occurrences of undici using npm ls undici.
- Modify package.json to override transitive references or directly run npm update undici.
- If deploying via Node.js system dependencies, upgrade the Node.js runtime binary to the latest LTS patch release.
- Deploy code changes and verify dependency resolutions using automated dependency scanners.
References
Read the full report for CVE-2026-85024 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)