LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-2229

nodejs · undici

Published
CVSS7.5
Severityhigh
WeaknessCWE-248
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). When the server subsequently sends a compressed frame, the client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination. The vulnerability exists b

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2229

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2229.