{"id":"CVE-2026-9675","title":"undici WebSocket client vulnerable to denial of service via cumulative fragment bypass","summary":"undici WebSocket client vulnerable to denial of service via cumulative fragment bypass","severity":"high","cvss":7.5,"cwe":["CWE-400","CWE-770"],"vendor":"undici","product":"undici","affected":["undici >= 8.0.0, < 8.5.0"],"patched":["undici 8.5.0"],"published":"2026-06-18","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-38rv-x7px-6hhq","references":[{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhq"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9675"},{"url":"https://cna.openjsf.org/security-advisories.html"},{"url":"https://github.com/advisories/GHSA-38rv-x7px-6hhq"}],"tags":["ghsa","npm"],"epss":0.00426,"epssPercentile":0.36379,"ingestedAt":"2026-06-19T03:39:00.824Z","ecosystem":"npm","slug":"CVE-2026-9675","body":"## Overview\n\n## Impact\n\nThe undici WebSocket client enforces `maxPayloadSize` per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but collectively exceed the configured limit, causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client (`new WebSocket(...)`) that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\nThis is a regression specific to undici 8.1.0. The 6.25.0 line shipped the equivalent cumulative check from the start and is unaffected. The 7.x line never had the `maxPayloadSize` feature and is also unaffected.\n\n## Patches\n\nUpgrade to undici >= 8.5.0.\n\n## Workarounds\n\nNo workaround is available. The fix must be applied through an upgrade.\n\n## Affected packages\n\n- `undici >= 8.0.0, < 8.5.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `undici 8.5.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}