CVE-2026-12151Disclosure(nodejs / undici)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-06-17); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-06-17: 3Mentions · 2026-06-18: 1Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-17: 3Technical Details · 2026-06-18: 106-1706-1806-2506-27
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-173
Disclosure2Patch1
2026-06-181
Disclosure1
2026-06-251
Patch1
2026-06-271
Patch1
Full discourse6 posts
  • Matteo Collina@matteocollina
    Disclosure

    🟠 High: WebSocket DoS (CVE-2026-12151). A malicious server could send unlimited tiny/empty fragments. We capped total payload size but not fragment *count* → unbounded memory growth. Affects v6/v7/v8. No workaround — upgrade.

    Post summary

    CVE-2026-12151 is a high‑severity WebSocket DoS that allows a malicious server to cause unbounded memory growth by sending endless tiny fragments; affected versions v6, v7, and v8; only mitigation is to upgrade.

    100401.1K
    57.8K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in undici (6.26.0, 7.28.0, 8.5.0) just released! Patches CVE-2026-12151. undici WebSocket client vulnerable to denial of service via fragment count bypass. https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q

    Post summary

    The announcement details a high‑severity patch for CVE-2026-12151, fixing a denial of service flaw in the undici WebSocket client; no active exploitation is reported and no PoC is shared.

    01020224
    5.5K followersView on X
  • MX3 Dev@Mx3Dev
    Patch

    @mem0ai Fixes & security → Validate and trim entity IDs on deleteAll → Fix Redis insert/update crash on missing hash/timestamps → Bump undici to patch CVE-2026-12151.

    Post summary

    The tweet announces that a library update (undici) is applied to patch CVE‑2026‑12151, with no indication of an active exploit or PoC.

    1000048
    130 followersView on X
  • RazzReport@RazzReport
    Patch

    OpenHands patched 4 CVEs in one window (CVE-2026-44681, 53571, 48712, 54285). Mem0 fixed CVE-2026-12151 (undici). LiteLLM has client key leak redaction in flight. Unusual concentration - possibly coordinated disclosure or shared dependency. @LiteLLM

    Post summary

    The excerpt announces that OpenHands and Mem0 have applied patches to several CVEs, but provides no exploitation or vulnerability detail.

    1000051
    14 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragm… https://www.cve.org/CVERecord?id=CVE-2026-12151 ----- Traducción: Impacto de CVE-202… http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-12151) affecting the undici WebSocket client was disclosed, noting an incomplete enforcement of fragment limits. No PoC, exploit, patch, or active exploitation details are provided.

    0000035
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragm… https://www.cve.org/CVERecord?id=CVE-2026-12151

    Post summary

    CVE-2026-12151 reveals that the undici WebSocket client limits payload size by total bytes but ignores fragment count, potentially enabling denial‑of‑service attacks.

    00000256
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more