{"id":"GHSA-38rv-x7px-6hhq","summary":"undici WebSocket client vulnerable to denial of service via cumulative fragment bypass","details":"## Impact\n\nThe undici WebSocket client enforces `maxPayloadSize` per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but collectively exceed the configured limit, causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client (`new WebSocket(...)`) that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\nThis is a regression specific to undici 8.1.0. The 6.25.0 line shipped the equivalent cumulative check from the start and is unaffected. The 7.x line never had the `maxPayloadSize` feature and is also unaffected.\n\n## Patches\n\nUpgrade to undici \u003e= 8.5.0.\n\n## Workarounds\n\nNo workaround is available. The fix must be applied through an upgrade.","aliases":["CVE-2026-9675"],"modified":"2026-06-18T14:41:37.218731Z","published":"2026-06-18T14:28:10Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-18T14:28:10Z","nvd_published_at":"2026-06-17T17:17:28Z","cwe_ids":["CWE-400","CWE-770"]},"references":[{"type":"WEB","url":"https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9675"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/nodejs/undici"}],"affected":[{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38rv-x7px-6hhq/GHSA-38rv-x7px-6hhq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}