Undici WS Client Unbounded Fragment Size Causes DOS (v6.x8.x)
CVE-2026-12151 Published on June 17, 2026
undici WebSocket client vulnerable to denial of service via fragment count bypass
Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.
Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.
All releases starting at undici 6.17.0 are affected.
Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:
No workaround is available. The fix must be applied through an upgrade.
Vulnerability Analysis
CVE-2026-12151 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Types
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-12151 has been classified to as a Resource Exhaustion vulnerability or weakness.
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2026-12151
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
undici:- Before 6.26.0 is affected.
- Version 6.26.0 is unaffected.
- Version 7.0.0 and below 7.28.0 is affected.
- Version 7.28.0 is unaffected.
- Version 8.0.0 and below 8.5.0 is affected.
- Version 8.5.0 is unaffected.
- Version 4.2.0-13 and below * is unaffected.
- Version 1:24.18.0-1.el10_2 and below * is unaffected.
- Version 1:22.23.1-2.el10_2 and below * is unaffected.
- Version 1:22.23.1-2.el10_0 and below * is unaffected.
- Version 8100020260630152626.6d880403 and below * is unaffected.
- Version 8100020260703140402.6d880403 and below * is unaffected.
- Version 9080020260626074955.rhel9 and below * is unaffected.
- Version 9080020260626075442.rhel9 and below * is unaffected.
- Version 9060020260804140259.rhel9 and below * is unaffected.
- Version 1782840519 and below * is unaffected.
- Version 1782839981 and below * is unaffected.
- Version 1782839193 and below * is unaffected.
- Version 1782838753 and below * is unaffected.
- Version 1782839279 and below * is unaffected.
- Version 1782840539 and below * is unaffected.
- Version 1782841925 and below * is unaffected.
- Version 1782844225 and below * is unaffected.
- Version 1782839658 and below * is unaffected.
- Version 1782838476 and below * is unaffected.
- Version 1782839996 and below * is unaffected.
- Version 1782839494 and below * is unaffected.
- Version 1783448184 and below * is unaffected.
- Version 1784210921 and below * is unaffected.
- Version 26.5.0-1.3.hum1 and below * is unaffected.
- Version 24.18.0-0.3.hum1 and below * is unaffected.
- Version 1783306396 and below * is unaffected.
- Version 1784744859 and below * is unaffected.
- Version 1786705347 and below * is unaffected.
- Version 1786706101 and below * is unaffected.
- Version 1786705558 and below * is unaffected.
- Version 1786705646 and below * is unaffected.
- Version 1786706138 and below * is unaffected.
- Version 1786705741 and below * is unaffected.
- Version 1786705777 and below * is unaffected.
- Version 1786705802 and below * is unaffected.
- Version 1786705938 and below * is unaffected.
- Version 1786706577 and below * is unaffected.
- Version 1786706125 and below * is unaffected.
- Version 1786706177 and below * is unaffected.
- Version 1786706188 and below * is unaffected.
- Version 1786706679 and below * is unaffected.
- Version 1786706357 and below * is unaffected.
- Version 1786706612 and below * is unaffected.
- Version 1786706644 and below * is unaffected.
- Version 1786706659 and below * is unaffected.
- Version 1786706880 and below * is unaffected.
- Version 1786701839 and below * is unaffected.
- Version 1786701555 and below * is unaffected.
- Version 1786702052 and below * is unaffected.
- Version 1786702559 and below * is unaffected.
- Version 1786702713 and below * is unaffected.
- Version 1786702264 and below * is unaffected.
- Version 1786702448 and below * is unaffected.
- Version 1786702276 and below * is unaffected.
- Version 1786702440 and below * is unaffected.
- Version 1786702315 and below * is unaffected.
- Version 1786703071 and below * is unaffected.
- Version 1786702563 and below * is unaffected.
- Version 1786702636 and below * is unaffected.
- Version 1786702623 and below * is unaffected.
- Version 1786703137 and below * is unaffected.
- Version 1786702716 and below * is unaffected.
- Version 1786702872 and below * is unaffected.
- Version 1786702949 and below * is unaffected.
- Version 1786702917 and below * is unaffected.
- Version 1786703143 and below * is unaffected.
- Version 1786627460 and below * is unaffected.
- Version 1786626399 and below * is unaffected.
- Version 1786628235 and below * is unaffected.
- Version 1786627106 and below * is unaffected.
- Version 1786629761 and below * is unaffected.
- Version 1786627559 and below * is unaffected.
- Version 1786687918 and below * is unaffected.
- Version 1786629478 and below * is unaffected.
- Version 1786628142 and below * is unaffected.
- Version 1786631508 and below * is unaffected.
- Version 1786628053 and below * is unaffected.
- Version 1786627382 and below * is unaffected.
- Version 1786627430 and below * is unaffected.
- Version 1786629076 and below * is unaffected.
- Version 1786627469 and below * is unaffected.
- Version 1786644072 and below * is unaffected.
- Version 1786688215 and below * is unaffected.
- Version 1786628340 and below * is unaffected.
- Version 1786628623 and below * is unaffected.
- Version 1786632256 and below * is unaffected.
- Version 1786628935 and below * is unaffected.
- Version 1786629548 and below * is unaffected.
- Version 1782498792 and below * is unaffected.
- Version 1783007534 and below * is unaffected.
- Version 1782989367 and below * is unaffected.
- Version 1785245777 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.