CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-85024

CVE-2026-85024: Denial of Service via Uncaught Exception in undici WebSocket Client

Alon Barad
Alon Barad
Software Engineer

Sep 28, 2026·7 min read·4 visits

Executive Summary (TL;DR)

A race condition in undici's permessage-deflate cleanup allows remote servers to crash Node.js applications by sending an over-limit payload followed by trailing malformed bytes, triggering an uncaught exception.

A high-severity Denial of Service (DoS) vulnerability exists in the undici WebSocket client implementation when processing compressed frames. The vulnerability is caused by a race condition where event listeners, including error handlers, are stripped from the active zlib stream during cleanup before the stream is fully terminated, leading to an unhandled exception.

Vulnerability Overview

The undici library serves as the default, highly optimized HTTP/1.1, HTTP/2, and WebSocket client built into the Node.js runtime environment. When WebSocket connections are established with the permessage-deflate extension enabled, undici handles compression and decompression of payloads automatically. This architectural component is exposed to remote, untrusted inputs over network channels, presenting an attack surface if payload validation is bypassed or mismanaged.

CVE-2026-85024 describes a high-severity Denial of Service vulnerability within undici's WebSocket decompression logic. The vulnerability manifests during the processing of incoming binary or text frames that have been compressed using the DEFLATE algorithm. When a remote endpoint sends a payload that expands beyond configured safety thresholds, the client initiates an improper teardown of the active decompression stream.

This flaw resides in the category of uncaught exceptions (CWE-248). Due to asynchronous processing characteristics in Node.js, the premature termination of event listeners leaves the application vulnerable to delayed runtime errors. An attacker can systematically trigger this state to terminate the Node.js process, causing a complete loss of service availability.

Root Cause Analysis

To prevent resource exhaustion from compression attacks, such as decompression loops or zip bombs, undici enforces a maxPayloadSize constraint on decompressed frames. The library utilizes Node.js's native zlib.InflateRaw class to process compressed data streams. If the volume of decompressed bytes exceeds the limit during inflation, the library triggers a cleanup routine to discard the stream and reclaim resources.

In the vulnerable implementation, this cleanup mechanism executed this.#inflate.removeAllListeners() and set the reference to null. This call immediately detached the data, close, and error listeners from the InflateRaw instance. The design expected that the stream would cease operations immediately and be queued for garbage collection, preventing further event emission.

However, Node.js delegates native zlib operations to the libuv threadpool to run asynchronously, avoiding blocking the main JavaScript execution thread. Consequently, calling removeAllListeners() does not halt or cancel the decompression operations already queued or active within the libuv worker threads. If the input buffer contains trailing invalid DEFLATE sequences, the native decompressor continues processing and eventually encounters a Z_DATA_ERROR condition.

Because the JavaScript-level error listener was prematurely removed, the stream's subsequent error event has no registered handler. In Node.js, an unhandled error event on any EventEmitter subclass, including streams, escalates to an uncaught exception. This failure to handle the runtime error results in the immediate, non-graceful termination of the entire Node.js process.

Code Analysis

Analyzing the vulnerable implementation in lib/web/websocket/permessage-deflate.js highlights how the stream lifecycle was mismanaged. When the decompressed output exceeded maxPayloadSize, the logic discarded the stream state without ensuring synchronous termination. The code block below represents the vulnerable implementation where listeners are detached while active work is still pending in the threadpool.

// Vulnerable Code Path
if (this.#maxPayloadSize > 0 && this.#inflate[kLength] > this.#maxPayloadSize) {
  callback(new MessageSizeExceededError())
  // Detaches the 'error' listener prematurely
  this.#inflate.removeAllListeners()
  this.#inflate = null
  return
}

The corresponding patch introduces a synchronous call to the destroy() method on the stream object. This addition ensures that the underlying native zlib context handle is immediately invalidated and freed, preventing further worker pool execution. Below is the updated and safe implementation showing the sequence of operations required to prevent late-stage error emissions.

// Patched Code Path
if (this.#maxPayloadSize > 0 && this.#inflate[kLength] > this.#maxPayloadSize) {
  callback(new MessageSizeExceededError())
  // Remove data listeners first
  this.#inflate.removeAllListeners()
  // Synchronously destroy the stream to abort threadpool operations
  this.#inflate.destroy()
  this.#inflate = null
  return
}

The integration of this.#inflate.destroy() resolves the vulnerability entirely. It provides a deterministic barrier against late-stage stream errors by immediately canceling the active zlib context. This prevents the worker thread from writing any further output or raising a Z_DATA_ERROR asynchronously, thus neutralizing the uncaught exception vector.

Exploitation

Exploitation of CVE-2026-85024 relies on the asymmetric nature of DEFLATE compression to construct highly efficient payload structures. An attacker must first establish or hijack a WebSocket connection with a client using an affected version of undici. The target connection must have negotiation parameters that permit the permessage-deflate extension.

To construct the attack vector, the attacker generates a payload consisting of two distinct segments. The first segment contains highly redundant data, such as a repeating sequence of null bytes, which compresses with an extremely high ratio. A payload of roughly 130 KB on the wire can decompress to exceed the default 128 MiB maxPayloadSize threshold. The second segment, placed immediately after the redundant data, consists of an invalid DEFLATE block designed to trigger a parser error.

When the client decompressor processes the first segment, the accumulated size exceeds the configured limit, triggering the cleanup sequence and removing the event listeners. The libuv worker thread then immediately encounters the trailing invalid DEFLATE bytes in the pipeline, generating a Z_DATA_ERROR. Since the error handler has been removed, the unhandled error event bubbles up to the root process, terminating the client application.

Impact Assessment

The impact of CVE-2026-85024 is classified as a complete Denial of Service (DoS) affecting the availability of the hosting application. Because undici is integrated as the default HTTP and WebSocket client in modern Node.js runtimes, any client-side WebSocket communication that connects to external, untrusted, or compromised servers is vulnerable. The vulnerability does not require authentication or specific privilege levels on the target client.

The Common Vulnerability Scoring System (CVSS) v3.1 base score of 5.9 reflects this profile. The attack vector is Network (AV:N), requiring no local access, and requires no User Interaction (UI:N). The attack complexity is rated as High (AC:H) due to the precise packet framing and sequence requirements necessary to trigger the race condition before stream destruction, though this is easily automated by an attacker.

While the scope remains Unchanged (S:U), the operational impact on production infrastructure can be severe. If the affected Node.js client has an automated reconnection policy, it will continuously re-establish the connection to the malicious endpoint and immediately crash again. This creates a loop of persistent denial of service, exhausting container orchestration resources and disrupting adjacent services.

Remediation

The primary and recommended remediation is to upgrade the undici package or the Node.js runtime to a patched version. The vulnerability has been resolved in undici versions 6.28.1, 7.29.1, and 8.10.2. Upgrading to these versions or higher ensures that the destroy() method is executed synchronously upon limit detection, preventing the unhandled stream error.

If a direct package upgrade is not feasible due to transitive dependency constraints, organizations can apply package resolutions or overrides. Adding an overrides block in package.json for NPM or a resolutions block for Yarn forces all nested instances of undici to resolve to a secure version. This method mitigates the risk across all dependency trees without requiring upstream maintainers to publish updates.

{
  "overrides": {
    "undici": "^6.28.1"
  }
}

Where runtime or library updates are entirely impossible, disabling the permessage-deflate extension during the WebSocket connection negotiation serves as an effective configuration workaround. Without compressed frames, the application does not instantiate the zlib InflateRaw decompression streams, completely removing the attack vector. This can be configured by omitting the perMessageDeflate options during the client initialization phase.

Official Patches

Node.js (undici)Release v6.28.1
Node.js (undici)Release v7.29.1
Node.js (undici)Release v8.10.2

Fix Analysis (3)

Technical Appendix

CVSS Score
5.9/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Probability
0.41%
Top 67% most exploited

Affected Systems

undici packages using WebSockets with permessage-deflate enabledNode.js instances using undici as native HTTP/WebSocket client

Affected Versions Detail

Product
Affected Versions
Fixed Version
undici
Node.js
>= 6.25.0, < 6.28.16.28.1
undici
Node.js
>= 7.28.0, < 7.29.17.29.1
undici
Node.js
>= 8.1.0, < 8.10.28.10.2
AttributeDetail
CWE IDCWE-248 (Uncaught Exception)
Attack VectorNetwork
CVSS v3.1 Score5.9 (Medium)
EPSS Score0.00412
Exploit StatusProof of Concept Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1499.004Endpoint Denial of Service: Application Denial of Service
Impact
CWE-248
Uncaught Exception

The product does not handle or incorrectly handles an exceptional condition, leading to an unhandled exception and potential application crash.

Vulnerability Timeline

Vulnerability identified and preliminary patch work started
2026-08-31
Official fix commit authored and merged
2026-09-03
CVE Published to NVD and GitHub Security Advisory released
2026-09-04
CVE record updated with complete CVSS metrics
2026-09-16

References & Sources

  • [1]GitHub Security Advisory GHSA-3wwx-pv8p-q78v
  • [2]OpenJSF Security Directory
  • [3]NVD Details

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•44 minutes ago•CVE-2026-88932
5.3

CVE-2026-88932: Uncontrolled Resource Consumption (Denial of Service) via orphaned disk writes on aborted uploads in multer

An uncontrolled resource consumption vulnerability exists in the multer middleware for Node.js (versions 2.2.0 through 2.3.0) when handling aborted multipart uploads using disk storage. Due to an asynchronous race condition in path resolution, files can become permanently orphaned on disk, leading to storage exhaustion and denial of service.

Alon Barad
Alon Barad
3 views•6 min read
•about 3 hours ago•GHSA-6VJ9-MWQ6-2F5V
5.9

GHSA-6VJ9-MWQ6-2F5V: Cross-Tenant SMTP Credential Disclosure via Shared-State DNS Cache Pollution in Nodemailer

Nodemailer versions 5.0.0 up to 10.0.1 are vulnerable to process-global state contamination inside the DNS caching subsystem. When SMTPS connections are established in a multi-tenant Node.js process targeting a shared gateway, a lower-privilege attacker can seed the global DNS cache with a malicious TLS servername. When a victim subsequently resolves the same gateway host, Nodemailer retrieves the polluted servername, overwrites the victim's connection settings, redirects the TLS session to the attacker's virtual host, and transmits the victim's cleartext SMTP credentials directly to the attacker.

Alon Barad
Alon Barad
7 views•7 min read
•about 4 hours ago•CVE-2026-83557
5.6

CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable

An incomplete denylist vulnerability in FasterXML jackson-databind's DefaultBaseTypeLimitingValidator allows unauthenticated remote attackers to bypass polymorphic type limitations. By declaring properties of type java.lang.Comparable, attackers can instantiate arbitrary Comparable subclasses on the classpath, leading to path traversal, local file access, or application-specific state manipulation.

Alon Barad
Alon Barad
8 views•6 min read
•about 5 hours ago•CVE-2026-101914
6.5

CVE-2026-101914: Authorization Bypass via Case-Insensitive Path Matching in @grpc/grpc-js-xds

An authorization bypass vulnerability exists in the @grpc/grpc-js Node.js package (specifically within the xDS plugin wrapper @grpc/grpc-js-xds) due to a logical error in its Role-Based Access Control (RBAC) path matching component. When case-insensitive path matching is enabled, the matching logic performs a prefix comparison using the startsWith method instead of a strict equality comparison. This logic flaw allows unauthenticated or low-privilege clients with access to a shorter path to gain unauthorized access to longer, more privileged method names that share the same prefix.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 10 hours ago•CVE-2026-61834
4.3

CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch

A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.

Alon Barad
Alon Barad
7 views•6 min read
•about 11 hours ago•GHSA-456V-XQ2P-R4CJ
7.8

GHSA-456V-XQ2P-R4CJ: OS Command Injection in code-ollama grep_search Tool

An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.

Amit Schendel
Amit Schendel
8 views•5 min read