{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/undici--7.24.1--7.29.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-19534"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["undici (\u003e= 6.7.0, \u003c 6.28.1)","undici (\u003e= 7.0.0, \u003c 7.29.1)","undici (\u003e= 8.0.0, \u003c 8.10.2)","undici (\u003e= 7.24.1, \u003c 7.29.1)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","tls","nodejs"],"_cs_type":"advisory","_cs_vendors":["OpenJS Foundation"],"content_html":"\u003cp\u003eThe undici package, a popular HTTP/1.1 and WebSocket client for Node.js, contains a flaw in its WebSocket implementation that results in a process-wide denial of service. When establishing a WebSocket connection, the library fails to properly handle unexpected \u003ccode\u003eSec-WebSocket-Protocol\u003c/code\u003e headers returned by a server in its \u003ccode\u003e101 Switching Protocols\u003c/code\u003e response. Specifically, if the client did not request a subprotocol but the server includes one, the internal logic throws an uncaught \u003ccode\u003eTypeError\u003c/code\u003e within a \u003ccode\u003equeueMicrotask\u003c/code\u003e callback.\u003c/p\u003e\n\u003cp\u003eBecause this error occurs outside of a standard \u003ccode\u003etry\u003c/code\u003e/\u003ccode\u003ecatch\u003c/code\u003e block, it results in an unhandled exception that causes the entire Node.js runtime to terminate. This vulnerability, tracked as CVE-2026-19534, can be exploited by an attacker operating a malicious WebSocket server or by an adversary performing a machine-in-the-middle attack on unencrypted \u003ccode\u003ews://\u003c/code\u003e connections. Affected versions include all releases from 6.7.0 through those immediately preceding 6.28.1, 7.29.1, and 8.10.2. Defenders should prioritize patching, as there is no viable workaround for this flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for remote, unauthenticated denial of service against any application utilizing the undici WebSocket client. Successful exploitation results in immediate application downtime due to process termination. This represents a significant availability risk for services that programmatically connect to external or untrusted third-party WebSocket endpoints.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade vulnerable installations of undici to version 6.28.1, 7.29.1, or 8.10.2 to remediate CVE-2026-19534.\u003c/li\u003e\n\u003cli\u003eAudit application codebases to identify instances where the \u003ccode\u003enew WebSocket(url)\u003c/code\u003e constructor is used to connect to third-party or untrusted server endpoints.\u003c/li\u003e\n\u003cli\u003eEnforce TLS (wss://) for all WebSocket connections to mitigate the risk of machine-in-the-middle injection of the malicious \u003ccode\u003eSec-WebSocket-Protocol\u003c/code\u003e header.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T22:18:37Z","date_published":"2026-09-29T22:18:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-undici-dos/","summary":"The undici WebSocket client library is vulnerable to a denial-of-service attack (CVE-2026-19534) that crashes the Node.js process when a server returns an unrequested Sec-WebSocket-Protocol header.","title":"Undici WebSocket Client Denial of Service via Unsolicited Subprotocol","url":"https://feed.craftedsignal.io/briefs/2026-09-undici-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Undici (\u003e= 7.24.1, \u003c 7.29.1)","version":"https://jsonfeed.org/version/1.1"}