## Impact The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (`new WebSocket(...)`) or the `WebSocketStream` API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. ## Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ## Workarounds No workaround is available. The fix must be applied through an upgrade.
Update undici to 6.27.0; undici to 7.28.0; undici to 8.5.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanundici WebSocket client vulnerable to denial of service via fragment count bypass affects undici (npm), undici (npm), undici (npm). Severity is high. ## Impact The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (`new WebSocket(...)`) or the `WebSocketStream` API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. ## Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ## Workarounds No workaround is available. The fix must be applied through an upgrade.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
## Impact The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (`new WebSocket(...)`) or the `WebSocketStream` API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. ## Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ## Workarounds No workaround is available. The fix must be applied through an upgrade.
Update undici to 6.27.0; undici to 7.28.0; undici to 8.5.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanundici WebSocket client vulnerable to denial of service via fragment count bypass affects undici (npm), undici (npm), undici (npm). Severity is high. ## Impact The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (`new WebSocket(...)`) or the `WebSocketStream` API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. ## Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ## Workarounds No workaround is available. The fix must be applied through an upgrade.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
| Fixed version |
|---|
| undicinpm | <6.27.0 | 6.27.0 |
|---|---|---|
| undicinpm | >=7.0.0,<7.28.0 | 7.28.0 |
| undicinpm | >=8.0.0,<8.5.0 | 8.5.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Fixed version |
|---|
| undicinpm | <6.27.0 | 6.27.0 |
|---|---|---|
| undicinpm | >=7.0.0,<7.28.0 | 7.28.0 |
| undicinpm | >=8.0.0,<8.5.0 | 8.5.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard