CyberRota Analysis
AI-GeneratedThe undici WebSocket client is vulnerable to a crash during the opening handshake when a server responds with an unexpected subprotocol, leading to an uncaught TypeError that terminates the Node.js process. This issue can be exploited remotely by any application that connects to a malicious or compromised WebSocket server, particularly over unencrypted connections. Organizations using affected versions of undici (6.7.0 to 6.28.1, 7.0.0 to 7.29.1, and 8.0.0 to 8.10.2) should prioritize upgrading to the patched versions to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
Related CVEs
Other vulnerabilities affecting the same vendor(s)