CVE-2026-22036
published 2026-01-14CVE-2026-22036: Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
34.9th percentile
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-undici | < node-undici 7.18.2+dfsg+~cs3.2.0-1 (forky) | node-undici 7.18.2+dfsg+~cs3.2.0-1 (forky) |
| nodejs | undici | < 6.23.0 | 6.23.0 |
| nodejs | undici | — | — |
| nodejs | undici | >= 0 < 6.23.0 | 6.23.0 |
| nodejs | undici | >= 7.0.0 < 7.18.2 | 7.18.2 |
| nodejs | undici | >= 7.0.0 < 7.18.2 | 7.18.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa6.5MEDIUM
osv7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
osv·2026-01-14·CVSS 6.5
CVE-2026-22036 [MEDIUM] Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
### Impact
The `fetch()` API supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., Content-Encoding: gzip, br). This is also supported by the undici decompress interceptor.
However, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation.
### Patches
Upgrade to 7.18.2 or 6.23.0.
### Workarounds
It is possible to apply an undici interceptor and filter long `Content-Encoding` sequences manually.
### References
* https://hackerone.com/reports/3456148
* https://gi
OSV
CVE-2026-22036: Undici is an HTTP/1
osv·2026-01-14·CVSS 7.5
CVE-2026-22036 [HIGH] CVE-2026-22036: Undici is an HTTP/1
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
GHSA
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
ghsa·2026-01-14·CVSS 6.5
CVE-2026-22036 [MEDIUM] CWE-770 Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
### Impact
The `fetch()` API supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., Content-Encoding: gzip, br). This is also supported by the undici decompress interceptor.
However, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation.
### Patches
Upgrade to 7.18.2 or 6.23.0.
### Workarounds
It is possible to apply an undici interceptor and filter long `Content-Encoding` sequences manually.
### References
* https://hackerone.com/reports/3456148
* https://gi
Red Hat
undici: Undici: Denial of Service via excessive decompression steps
vendor_redhat·2026-01-14·CVSS 5.9
CVE-2026-22036 [MEDIUM] CWE-770 undici: Undici: Denial of Service via excessive decompression steps
undici: Undici: Denial of Service via excessive decompression steps
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
A flaw was found in Undici, an HTTP/1.1 client for Node.js. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP response with an unbounded number of links in the decompression chain. This could lead to high CPU usage and excessive memory allocation, resulting in a Denial of Service (DoS) for the affected system.
Statement: This vulnerability is rated Low for
Debian
CVE-2026-22036: node-undici - Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number...
vendor_debian·2026·CVSS 5.9
CVE-2026-22036 [MEDIUM] CVE-2026-22036: node-undici - Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number...
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
Scope: local
bookworm: open
forky: resolved (fixed in 7.18.2+dfsg+~cs3.2.0-1)
sid: resolved (fixed in 7.18.2+dfsg+~cs3.2.0-1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-22036 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-22036 [MEDIUM] CVE-2026-22036 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22036 :
JavaScript vulnerability analysis and mitigation
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
Source : NVD
## 7.5
Score
Published January 14, 2026
Severity HIGH
CNA Score 5.9
Affected Technologies
JavaScript
Node.js
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
npm20
npm22
Sources
NVD
Chainguard Has Fix
Bugzilla
CVE-2026-22036 undici: Undici: Denial of Service via excessive decompression steps
bugzilla·2026-01-14·CVSS 7.5
CVE-2026-22036 [HIGH] CVE-2026-22036 undici: Undici: Denial of Service via excessive decompression steps
CVE-2026-22036 undici: Undici: Denial of Service via excessive decompression steps
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
2026-01-14
Published