{"id":"GHSA-3wwx-pv8p-q78v","summary":"undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression","details":"## Impact\n\nundici's WebSocket client (including Node.js's bundled `globalThis.WebSocket`) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. In `lib/web/websocket/permessage-deflate.js`, the size-limit cleanup calls `removeAllListeners()` on the internal zlib `InflateRaw`, removing its `error` listener, but leaves the stream running. The inflater then emits a `Z_DATA_ERROR` with no listener attached, which Node.js treats as a fatal unhandled `error` event and terminates the process. Application `error`/`close` handlers on the public WebSocket cannot observe or prevent this, because the failing object is the internal `InflateRaw`.\n\nA malicious or compromised WebSocket server can crash a client with a single connection, unauthenticated and without any application mistake. The attack is asymmetric (about 130 KB on the wire expands past the limit) and can be repeated on reconnect (crash loop).\n\nAffected applications are those using the undici WebSocket client (`new WebSocket(...)`) or Node.js's bundled `globalThis.WebSocket` that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\n## Patches\n\nUpgrade to undici v6.28.1, v7.29.1 or v8.10.2.\n\n## Workarounds\n\nNo workaround is available.","aliases":["CVE-2026-85024"],"modified":"2026-09-28T22:00:05.388362995Z","published":"2026-09-28T21:42:37Z","database_specific":{"nvd_published_at":"2026-09-04T17:17:02Z","cwe_ids":["CWE-248"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-28T21:42:37Z"},"references":[{"type":"WEB","url":"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85024"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/nodejs/undici"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v6.28.1"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v7.29.1"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v8.10.2"}],"affected":[{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.25.0"},{"fixed":"6.28.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json"}},{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.28.0"},{"fixed":"7.29.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json"}},{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.1.0"},{"fixed":"8.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}