CyberRota Analysis
AI-GeneratedThe vulnerability affects undici versions 6.25.0 to 6.28.1, 7.28.0 to 7.29.1, and 8.1.0 to 8.10.2, allowing remote, unauthenticated attackers to exploit a flaw in the WebSocket client that can lead to a process crash. When a malformed DEFLATE byte is sent in a compressed payload exceeding the 128 MiB limit, the absence of an error listener results in an unhandled error that terminates the Node.js process. Organizations using affected versions should prioritize upgrading to undici 6.28.1, 7.29.1, or 8.10.2 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
Related CVEs
Other vulnerabilities affecting the same vendor(s)