GHSA-3wwx-pv8p-q78v

Suggest an improvement
Source
https://github.com/advisories/GHSA-3wwx-pv8p-q78v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3wwx-pv8p-q78v
Aliases
Downstream
CGA (26)
ECHO (1)
MINI (1)
Published
2026-09-28T21:42:37Z
Modified
2026-09-28T22:00:08Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Details

Impact

undici's WebSocket client (including Node.js's bundled globalThis.WebSocket) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. In lib/web/websocket/permessage-deflate.js, the size-limit cleanup calls removeAllListeners() on the internal zlib InflateRaw, removing its error listener, but leaves the stream running. The inflater then emits a Z_DATA_ERROR with no listener attached, which Node.js treats as a fatal unhandled error event and terminates the process. Application error/close handlers on the public WebSocket cannot observe or prevent this, because the failing object is the internal InflateRaw.

A malicious or compromised WebSocket server can crash a client with a single connection, unauthenticated and without any application mistake. The attack is asymmetric (about 130 KB on the wire expands past the limit) and can be repeated on reconnect (crash loop).

Affected applications are those using the undici WebSocket client (new WebSocket(...)) or Node.js's bundled globalThis.WebSocket that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.

Patches

Upgrade to undici v6.28.1, v7.29.1 or v8.10.2.

Workarounds

No workaround is available.

Database specific
{
    "cwe_ids":  [
        "CWE-248"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-28T21:42:37Z",
    "nvd_published_at":  "2026-09-04T17:17:02Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / undici

Package

Affected ranges

Type
SEMVER
Events
Introduced
6.25.0
Fixed
6.28.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json"

npm / undici

Package

Affected ranges

Type
SEMVER
Events
Introduced
7.28.0
Fixed
7.29.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json"

npm / undici

Package

Affected ranges

Type
SEMVER
Events
Introduced
8.1.0
Fixed
8.10.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3wwx-pv8p-q78v/GHSA-3wwx-pv8p-q78v.json"