GHSA-rx4f-c7p8-82vq

Suggest an improvement
Source
https://github.com/advisories/GHSA-rx4f-c7p8-82vq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rx4f-c7p8-82vq/GHSA-rx4f-c7p8-82vq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rx4f-c7p8-82vq
Aliases
Published
2026-09-29T18:10:32Z
Modified
2026-09-29T18:15:04Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
undici vulnerable to Denial of Service via WebSocketStream unclean close
Details

Impact

undici's WebSocketStream crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls abort() on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with a TypeError, and the handler discards that promise. The unobserved rejection surfaces as an unhandledRejection and, under Node.js's default behavior, terminates the process.

A malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the WebSocketStream API and writing through a writer, which is the standard way to write.

All releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0.

Patches

Upgrade to undici v7.29.1 or v8.10.2.

Workarounds

No workaround is available.

Database specific
{
    "cwe_ids":  [
        "CWE-248",
        "CWE-754"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T18:10:32Z",
    "nvd_published_at":  "2026-09-04T17:17:02Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / undici

Package

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.29.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rx4f-c7p8-82vq/GHSA-rx4f-c7p8-82vq.json"

npm / undici

Package

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.10.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rx4f-c7p8-82vq/GHSA-rx4f-c7p8-82vq.json"