Allocation of Resources Without Limits or Throttling in undici - CVE-2026-2581

 

Allocation of Resources Without Limits or Throttling in undici - CVE-2026-2581

Published: April 24, 2026


Vulnerability identifier: #VU127580
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2581
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in DeduplicationHandler when processing deduplicated requests with large or chunked response bodies from an attacker-controlled or untrusted upstream endpoint. A remote attacker can trigger concurrent identical requests that cause response data to accumulate in memory to cause a denial of service.

Only applications with interceptors.deduplicate() enabled are vulnerable.


Affected software

undici
DataStage on Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
nodejs-npm
v8-12.4-devel
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-libs
nodejs-docs
nodejs24 (Red Hat package)

How to mitigate CVE-2026-2581

Install security update from vendor's website.

undici - update to 7.24.0
DataStage on Cloud Pak for Data - update to 5.3.1 patch 7
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1

External References

Related Security Bulletins