Improper Validation of Specified Quantity in Input in undici - CVE-2026-1528
Published: April 24, 2026
Vulnerability identifier: #VU127579
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1528
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in the ByteParser when processing a WebSocket frame with a 64-bit length field. A remote attacker can send an extremely large length value to cause a denial of service.
Affected software
undici
IBM Cloud Pak System
DataStage on Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Anolis OS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-npm
v8-12.4-devel
nodejs20
nodejs22 (Red Hat package)
nodejs22
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-libs
nodejs-docs
nodejs24 (Red Hat package)
IBM Cloud Pak System
DataStage on Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Anolis OS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-npm
v8-12.4-devel
nodejs20
nodejs22 (Red Hat package)
nodejs22
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-libs
nodejs-docs
nodejs24 (Red Hat package)
How to mitigate CVE-2026-1528
Install security update from vendor's website.
undici - addressed in versions 6.24.0, 7.24.0
IBM Cloud Pak System - update to 2.3.5.1
DataStage on Cloud Pak for Data - update to 5.4
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs20 - update to 20.20.2-3.fc43
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs22 - addressed in versions 22.22.2-2.fc43, 22.22.2-3.fc42, 22.22.2-3.fc44
nodejs - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
IBM Cloud Pak System - update to 2.3.5.1
DataStage on Cloud Pak for Data - update to 5.4
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs20 - update to 20.20.2-3.fc43
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs22 - addressed in versions 22.22.2-2.fc43, 22.22.2-3.fc42, 22.22.2-3.fc44
nodejs - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Fedora 43 update for nodejs20
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 10 update for nodejs24
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Fedora 44 update for nodejs22
- Fedora 43 update for nodejs22
- Multiple vulnerabilities in IBM Platform Navigator in IBM Cloud Pak for Integration (CP4I)
- Fedora 42 update for nodejs22
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System Software
- Anolis OS update for nodejs