<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Undici (&gt;= 8.0.0, &lt; 8.10.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/undici--8.0.0--8.10.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:18:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/undici--8.0.0--8.10.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Undici WebSocket Client Denial of Service via Unsolicited Subprotocol</title><link>https://feed.craftedsignal.io/briefs/2026-09-undici-dos/</link><pubDate>Tue, 29 Sep 2026 22:18:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-undici-dos/</guid><description>The undici WebSocket client library is vulnerable to a denial-of-service attack (CVE-2026-19534) that crashes the Node.js process when a server returns an unrequested Sec-WebSocket-Protocol header.</description><content:encoded><![CDATA[<p>The undici package, a popular HTTP/1.1 and WebSocket client for Node.js, contains a flaw in its WebSocket implementation that results in a process-wide denial of service. When establishing a WebSocket connection, the library fails to properly handle unexpected <code>Sec-WebSocket-Protocol</code> headers returned by a server in its <code>101 Switching Protocols</code> response. Specifically, if the client did not request a subprotocol but the server includes one, the internal logic throws an uncaught <code>TypeError</code> within a <code>queueMicrotask</code> callback.</p>
<p>Because this error occurs outside of a standard <code>try</code>/<code>catch</code> block, it results in an unhandled exception that causes the entire Node.js runtime to terminate. This vulnerability, tracked as CVE-2026-19534, can be exploited by an attacker operating a malicious WebSocket server or by an adversary performing a machine-in-the-middle attack on unencrypted <code>ws://</code> connections. Affected versions include all releases from 6.7.0 through those immediately preceding 6.28.1, 7.29.1, and 8.10.2. Defenders should prioritize patching, as there is no viable workaround for this flaw.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for remote, unauthenticated denial of service against any application utilizing the undici WebSocket client. Successful exploitation results in immediate application downtime due to process termination. This represents a significant availability risk for services that programmatically connect to external or untrusted third-party WebSocket endpoints.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade vulnerable installations of undici to version 6.28.1, 7.29.1, or 8.10.2 to remediate CVE-2026-19534.</li>
<li>Audit application codebases to identify instances where the <code>new WebSocket(url)</code> constructor is used to connect to third-party or untrusted server endpoints.</li>
<li>Enforce TLS (wss://) for all WebSocket connections to mitigate the risk of machine-in-the-middle injection of the malicious <code>Sec-WebSocket-Protocol</code> header.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>vulnerability</category><category>tls</category><category>nodejs</category></item></channel></rss>