CVE-2026-2229Disclosure(nodejs / undici)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). When the server subsequently sends a compressed frame, the client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination. The vulnerability exists because: * The isValidClientWindowBits() function only validates that the value contains ASCII digits, not that it falls within the valid range 8-15 * The createInflateRaw() call is not wrapped in a try-catch block * The resulting exception propagates up through the call stack and crashes the Node.js process

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 203-12
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in undici@7.24.0 just released! Patches CVE-2026-2229 — vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8

    Post summary

    A high‑severity fix for CVE‑2026‑2229 has been released in [email protected], addressing an unhandled exception in the WebSocket client.

    01020142
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2229 ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-defla… https://www.cve.org/CVERecord?id=CVE-2026-2229

    Post summary

    The text announces CVE-2026-2229 as a denial‑of‑service vulnerability in the undici WebSocket client, providing technical details but no proof of concept, exploit code, patch, or evidence of active exploitation.

    0000083
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more