CVE-2026-2581Disclosure(nodejs / undici)

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination. Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies. PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started. Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 203-12
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2581 This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.dedupli… https://www.cve.org/CVERecord?id=CVE-2026-2581

    Post summary

    The statement announces CVE-2026-2581 as an uncontrolled resource consumption vulnerability leading to DoS, linking only to the CVE record.

    00000101
    56.7K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in undici@7.24.0 just released! Patches CVE-2026-2581 — vulnerable to Unbounded memory consumption in deduplication interceptor response buffering (DoS risk). https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6h

    Post summary

    The advisory announces a medium‑severity patch for CVE‑2026‑2581, fixing unbounded memory consumption that could lead to a denial‑of‑service; no PoC, exploit, or active exploitation is mentioned.

    00000115
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more