Matteo Collina[verified]@matteocollinaDisclosure
CVE-2026-12151 is a high‑severity WebSocket DoS that allows a malicious server to cause unbounded memory growth by sending endless tiny fragments; affected versions v6, v7, and v8; only mitigation is to upgrade.
MX3 Dev[verified]@Mx3DevPatch
The tweet announces that a library update (undici) is applied to patch CVE‑2026‑12151, with no indication of an active exploit or PoC.
Ulises Gascón@kom_256Patch
The announcement details a high‑severity patch for CVE-2026-12151, fixing a denial of service flaw in the undici WebSocket client; no active exploitation is reported and no PoC is shared.
RazzReport@RazzReportPatch
The excerpt announces that OpenHands and Mem0 have applied patches to several CVEs, but provides no exploitation or vulnerability detail.
Infoflowcloud@infoflowcloudDisclosure
A new CVE (CVE-2026-12151) affecting the undici WebSocket client was disclosed, noting an incomplete enforcement of fragment limits. No PoC, exploit, patch, or active exploitation details are provided.
CVE@CVEnewDisclosure
CVE-2026-12151 reveals that the undici WebSocket client limits payload size by total bytes but ignores fragment count, potentially enabling denial‑of‑service attacks.