Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f269-vfmq-vjvj | Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client |
Fri, 20 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodejs
Nodejs undici |
|
| CPEs | cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nodejs
Nodejs undici |
Fri, 13 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Undici
Undici undici |
|
| Vendors & Products |
Undici
Undici undici |
Fri, 13 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 12 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later. | |
| Title | undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client | |
| Weaknesses | CWE-1284 CWE-248 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: openjs
Published:
Updated: 2026-03-13T13:04:57.048Z
Reserved: 2026-01-28T12:05:10.024Z
Link: CVE-2026-1528
Updated: 2026-03-13T13:04:19.272Z
Status : Analyzed
Published: 2026-03-12T21:16:25.330
Modified: 2026-03-20T15:41:40.110
Link: CVE-2026-1528
OpenCVE Enrichment
Updated: 2026-03-23T10:00:25Z
Github GHSA