Allocation of Resources Without Limits or Throttling in undici - CVE-2026-22036
Published: April 24, 2026
undici
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the fetch() API and undici decompress interceptor when processing HTTP responses with chained Content-Encoding values. A remote attacker can send a specially crafted response with thousands of compression steps to cause a denial of service.