SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85024

MEDIUM · CVSS 5.9 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects undici versions 6.25.0 to 6.28.1, 7.28.0 to 7.29.1, and 8.1.0 to 8.10.2, allowing remote, unauthenticated attackers to exploit a flaw in the WebSocket client that can lead to a process crash. When a malformed DEFLATE byte is sent in a compressed payload exceeding the 128 MiB limit, the absence of an error listener results in an unhandled error that terminates the Node.js process. Organizations using affected versions should prioritize upgrading to undici 6.28.1, 7.29.1, or 8.10.2 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85024
Severity
MEDIUM
CVSS
5.9
EPSS
0.26%

Original NVD Description

undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)