Bug 2489980 (CVE-2026-12151)

Summary: CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, alizardo, ataylor, cdrage, cmah, dbruscin, dschmidt, eaguilar, ebaron, ehugonne, erezende, jchui, jhe, jkoehler, jlanda, jmatsuok, jolong, jtolenti, kaycoth, kshier, ktsao, kvanderr, lphiri, manissin, nboldt, oaljalju, pjindal, psrna, rhel-process-autobot, rushinde, sdawley, simaishi, smcdonal, stcannon, teagle, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2490221, 2490223, 2490224, 2490225, 2490226    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-17 17:02:07 UTC
Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.

Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.

All releases starting at undici 6.17.0 are affected.

Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:
No workaround is available. The fix must be applied through an upgrade.

Comment 4 errata-xmlrpc 2026-07-06 04:36:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:35841 https://access.redhat.com/errata/RHSA-2026:35841

Comment 5 errata-xmlrpc 2026-07-06 05:16:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:35842 https://access.redhat.com/errata/RHSA-2026:35842

Comment 6 errata-xmlrpc 2026-07-06 14:23:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:35891 https://access.redhat.com/errata/RHSA-2026:35891

Comment 7 errata-xmlrpc 2026-07-06 14:44:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:35892 https://access.redhat.com/errata/RHSA-2026:35892

Comment 8 errata-xmlrpc 2026-07-14 12:31:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:39246 https://access.redhat.com/errata/RHSA-2026:39246

Comment 9 errata-xmlrpc 2026-07-15 11:23:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:39868 https://access.redhat.com/errata/RHSA-2026:39868

Comment 10 errata-xmlrpc 2026-07-20 13:06:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:41947 https://access.redhat.com/errata/RHSA-2026:41947

Comment 11 errata-xmlrpc 2026-07-29 19:55:34 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151

Comment 14 errata-xmlrpc 2026-08-10 02:41:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:52399 https://access.redhat.com/errata/RHSA-2026:52399