CVE-2026-1526Disclosure(nodejs / undici)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-13: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 1Technical Details · 2026-05-05: 103-1203-1305-05
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure1Patch1
2026-03-131
Disclosure1
2026-05-051
Disclosure1
Full discourse4 posts
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Fedora 43 and 44 ship Node.js 20 with multiple DoS flaws CVE-2026-21717, CVE-2026-21714, CVE-2026-1525, CVE-2026-1526, fixed in urgent 20.20.2 update. https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-nodejs-20-affe-ffaf0480

    Post summary

    Fedora 43 and 44 advertise that Node.js 20 contains multiple DoS flaws, which are fixed in an urgent 20.20.2 update; no PoC, exploit, or active exploitation is mentioned.

    0010050
    181 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1526 Denial-of-Service Vulnerability in Undici WebSocket Client via Permessage-Deflate Decompression https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1526

    Post summary

    A new denial‑of‑service flaw in the Undici WebSocket client, triggered by Permessage‑Deflate decompression, has been announced.

    0000075
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1526 The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket conne… https://www.cve.org/CVERecord?id=CVE-2026-1526

    Post summary

    The text announces a new CVE (CVE‑2026‑1526) describing a denial‑of‑service vulnerability in the undici WebSocket client.

    00000136
    56.7K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in undici@7.24.0 just released! Patches CVE-2026-1526 — vulnerable to Unbounded memory consumption in WebSocket permessage-deflate decompression. https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q

    Post summary

    An updated release of undici (v7.24.0) includes a high‑severity fix for CVE‑2026‑1526, which mitigates an unbounded memory consumption vulnerability in WebSocket permessage‑deflate decompression, with a reference to the official Node.js security advisory.

    00000101
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more