Back

HIGH

undici vulnerable to Denial of Service via WebSocketStream unclean close

Published Sep 4, 2026

Description

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

Affected products

Remediation

Red Hat statement

This Moderate impact flaw in the `undici` library's experimental `WebSocketStream` client can lead to a denial of service. An untrusted remote server can crash a vulnerable Node.js client application by abruptly closing a TCP connection without a WebSocket handshake. This affects the availability of applications utilizing `undici` in Red Hat products.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openjs
Published Sep 4, 2026
Updated Sep 4, 2026
Reserved Sep 2, 2026
CISA Vulnrichment
Updated Sep 4, 2026
NVD
Status Analyzed
Modified Sep 15, 2026
Red Hat
Severity Moderate
Public date Sep 4, 2026
ENISA EUVD
Assigner openjs
Published Sep 4, 2026
Updated Sep 4, 2026
Exploited since n/a
EUVD-2026-71465 GHSA-RX4F-C7P8-82VQ