CVE-2026-1528
published 2026-03-12CVE-2026-1528: ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.49%
38.6th percentile
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-undici | < node-undici 7.24.5+dfsg+~cs3.2.0-1 (forky) | node-undici 7.24.5+dfsg+~cs3.2.0-1 (forky) |
| nodejs | undici | < 6.24.0 | 6.24.0 |
| nodejs | undici | >= 7.0.0 < 7.24.0 | 7.24.0 |
| undici | undici | — | — |
| undici | undici | >= 6.0.0 < 6.24.0 | 6.24.0 |
| undici | undici | >= 7.0.0 < 7.24.0 | 7.24.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
ghsa·2026-03-13
CVE-2026-1528 [HIGH] CWE-1284 Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
### Impact
A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
### Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
### Workarounds
There are no workarounds.
OSV
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
osv·2026-03-13
CVE-2026-1528 [HIGH] Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
### Impact
A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
### Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
### Workarounds
There are no workarounds.
OSV
CVE-2026-1528: ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length
osv·2026-03-12·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528: ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Red Hat
undici: undici: Denial of Service via crafted WebSocket frame with large length
vendor_redhat·2026-03-12·CVSS 7.5
CVE-2026-1528 [HIGH] CWE-248 undici: undici: Denial of Service via crafted WebSocket frame with large length
undici: undici: Denial of Service via crafted WebSocket frame with large length
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici's ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.
Debian
CVE-2026-1528: node-undici - ImpactA server can reply with a WebSocket frame using the 64-bit length form and...
vendor_debian·2026·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528: node-undici - ImpactA server can reply with a WebSocket frame using the 64-bit length form and...
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Scope: local
bookworm: open
forky: resolved (fixed in 7.24.5+dfsg+~cs3.2.0-1)
sid: resolved (fixed in 7.24.5+dfsg+~cs3.2.0-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-1528 nodejs22: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all]
bugzilla·2026-03-12·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528 nodejs22: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all]
CVE-2026-1528 nodejs22: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-3b76d8047d (nodejs22-22.22.2-3.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-3b76d8047d
---
FEDORA-2026-e3f870229a (nodejs22-22.22.2-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-e3f870229a
Bugzilla
CVE-2026-1528 nodejs20: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all]
bugzilla·2026-03-12·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528 nodejs20: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all]
CVE-2026-1528 nodejs20: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9dc3a61ad8 (nodejs20-20.20.2-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9dc3a61ad8
---
FEDORA-2026-9dc3a61ad8 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9dc3a61ad8`
You can provide feedback for this update here: htt
Bugzilla
CVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large length
bugzilla·2026-03-12·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large length
CVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large length
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:7080 https://access.redhat.com/errata/RHSA-2026:7080
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:7123 https://access.redhat.com/errata/RHSA-2026:7123
---
This issue has been addr
Wiz
CVE-2026-1528 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1528 :
JavaScript vulnerability analysis and mitigation
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Source : NVD
## 7.5
Score
Published March 12, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
JavaScript
Node.js
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
nodejs:22::nodejs-devel
nodejs:2
https://cna.openjsf.org/security-advisories.htmlhttps://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvjhttps://hackerone.com/reports/3537648https://access.redhat.com/errata/RHSA-2026:13826https://access.redhat.com/errata/RHSA-2026:17789https://access.redhat.com/errata/RHSA-2026:21772https://access.redhat.com/errata/RHSA-2026:21931https://access.redhat.com/errata/RHSA-2026:34342https://access.redhat.com/errata/RHSA-2026:5807https://access.redhat.com/errata/RHSA-2026:7080https://access.redhat.com/errata/RHSA-2026:7123https://access.redhat.com/errata/RHSA-2026:7302https://access.redhat.com/errata/RHSA-2026:7310https://access.redhat.com/errata/RHSA-2026:7350https://access.redhat.com/errata/RHSA-2026:7670https://access.redhat.com/errata/RHSA-2026:7675https://access.redhat.com/errata/RHSA-2026:7983https://access.redhat.com/errata/RHSA-2026:9742https://access.redhat.com/security/cve/CVE-2026-1528https://bugzilla.redhat.com/show_bug.cgi?id=2447145https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1528.json
2026-03-12
Published