Bug 2528759 (CVE-2026-19534) - CVE-2026-19534 undici: undici: Denial of Service via unrequested WebSocket subprotocol
Summary: CVE-2026-19534 undici: undici: Denial of Service via unrequested WebSocket su...
Keywords:
Status: NEW
Alias: CVE-2026-19534
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2530856 2530858 2530859 2530857
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-04 17:25 UTC by OSIDB Bzimport
Modified: 2026-09-15 07:50 UTC (History)
56 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-04 17:25:49 UTC
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.


Note You need to log in before you can comment on or make changes to this bug.