Allocation of Resources Without Limits or Throttling in undici - CVE-2026-12151
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the WebSocket client message fragmentation handling when processing fragmented WebSocket messages from a server. A remote attacker can send many small or empty continuation frames to cause a denial of service.
Exploitation requires the application to connect to an attacker-controlled or compromised WebSocket endpoint using the WebSocket client or the WebSocketStream API.
Affected software
Netezza Appliance
Maximo Application Suite - Visual Inspection Component
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Fedora
Jira Service Management Data Center
Jira Software Data Center
Red Hat OpenShift Container Platform
nodejs22 (Red Hat package)
nodejs22
nodejs24
How to mitigate CVE-2026-12151
Netezza Appliance - update to 1.0.2.0
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.22, 9.1.19, 9.2.1
Jira Service Management Data Center - update to 11.3.10
Jira Software Data Center - update to 11.3.9
Red Hat OpenShift Container Platform - update to 4.16.66
nodejs22 (Red Hat package) - update to 22.23.1-2.el10_0
nodejs22 - update to 22.23.1-2.fc44
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM Netezza Appliance
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- Fedora 44 update for nodejs24
- Fedora 44 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module