CVE-2026-1528General(nodejs / undici)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 203-1203-13
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure1Patch1
2026-03-132
General2
Full discourse4 posts
  • AndrewMohawk⁽ⁿᵘˡˡ⁾@AndrewMohawk
    General

    Found another with @OpenAI Codex, this time in undici's ByteParser https://www.cve.org/CVERecord?id=CVE-2026-1528

    Post summary

    The tweet notes the discovery of CVE-2026-1528 in undici's ByteParser using OpenAI Codex, but provides no additional technical detail, PoC, patch information, or evidence of exploitation.

    03131133.7K
    5.2K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in undici@7.24.0 just released! Patches CVE-2026-1528 — vulnerable to Malicious WebSocket 64-bit frame length handling could crash the client. https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj

    Post summary

    A high‑severity security fix for undici 7.24.0 has been released, addressing CVE‑2026‑1528 which allows malicious WebSocket 64‑bit frame length handling to crash the client.

    01031191
    5.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1528 Undici WebSocket Frame Length Parsing Vulnerability Leading to Pro... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1528 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces CVE-2026-1528 and provides a link to vulnerability details and alert subscription, but offers no further technical or exploit information.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1528 ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an i… https://www.cve.org/CVERecord?id=CVE-2026-1528

    Post summary

    The CVE‑2026-1528 disclosure reveals an integer overflow in the undici ByteParser triggered by a WebSocket frame with an excessively large 64‑bit length, but no PoC, exploit, or mitigation details are provided.

    00000103
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more