cbcvebase.
CVE-2026-12151
published 2026-06-17

CVE-2026-12151: Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
42.9th percentile
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platformautomation-portal
ansible-automation-platformbootc-automation-portal-rhel9
devspacescode-rhel9
devspacesdashboard-rhel9
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
nodejsnodejs
nodejsundici>= 6.17.0 < 6.27.06.27.0
nodejsundici>= 7.0.0 < 7.28.07.28.0
nodejsundici>= 8.0.0 < 8.5.08.5.0
nodejs_22nodejs
nodejs_24nodejs
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9
openshift-pipelinespipelines-console-plugin-pf5-rhel9
openshift-pipelinespipelines-console-plugin-rhel8
openshift-pipelinespipelines-console-plugin-rhel9
openshift4ose-agent-installer-ui-rhel9
openshift4ose-console-rhel9
openshift4ose-monitoring-plugin-rhel9
rhdhrhdh-hub-rhel9
rhoaiodh-dashboard-rhel9
rhoaiodh-mod-arch-automl-rhel9
rhoaiodh-mod-arch-autorag-rhel9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvelistv5v3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.