CVE-2026-19534

Source
https://cve.org/CVERecord?id=CVE-2026-19534
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19534.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19534
Aliases
  • GHSA-rfgv-xxqx-mfg5
Downstream
Published
2026-09-04T17:10:05Z
Modified
2026-09-06T03:30:16Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
Details

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.

Database specific
{
    "cna_assigner": "openjs",
    "cwe_ids": [
        "CWE-248",
        "CWE-252"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19534.json"
}
References

Affected packages

Git / github.com/nodejs/undici

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/undici
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.7.0"
        },
        {
            "fixed": "6.28.1"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.29.1"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.10.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v6.*
v6.10.0
v6.10.1
v6.10.2
v6.11.0
v6.11.1
v6.12.0
v6.13.0
v6.14.0
v6.14.1
v6.15.0
v6.16.0
v6.16.1
v6.17.0
v6.18.0
v6.18.1
v6.18.2
v6.19.0
v6.19.1
v6.19.2
v6.19.3
v6.19.4
v6.19.5
v6.19.6
v6.19.7
v6.19.8
v6.20.0
v6.20.1
v6.21.0
v6.21.1
v6.21.2
v6.21.3
v6.22.0
v6.23.0
v6.24.0
v6.24.1
v6.25.0
v6.26.0
v6.27.0
v6.28.0
v6.7.0
v6.7.1
v6.8.0
v6.9.0
v7.*
v7.0.0
v7.1.0
v7.1.1
v7.10.0
v7.11.0
v7.12.0
v7.13.0
v7.14.0
v7.15.0
v7.16.0
v7.17.0
v7.18.0
v7.18.1
v7.18.2
v7.19.0
v7.19.1
v7.19.2
v7.2.0
v7.2.1
v7.2.2
v7.2.3
v7.20.0
v7.21.0
v7.22.0
v7.23.0
v7.24.0
v7.24.1
v7.24.2
v7.24.3
v7.24.4
v7.24.5
v7.24.6
v7.24.7
v7.24.8
v7.25.0
v7.26.0
v7.27.0
v7.27.1
v7.27.2
v7.28.0
v7.29.0
v7.3.0
v7.4.0
v7.5.0
v7.6.0
v7.7.0
v7.8.0
v7.9.0
v8.*
v8.0.0
v8.0.1
v8.0.2
v8.0.3
v8.1.0
v8.10.0
v8.10.1
v8.2.0
v8.3.0
v8.4.0
v8.4.1
v8.5.0
v8.6.0
v8.7.0
v8.8.0
v8.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19534.json"