Resource exhaustion in undici - CVE-2026-9675
Published: June 17, 2026
undici
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the WebSocket client when processing fragmented uncompressed messages. A remote attacker can stream many small WebSocket fragments to cause a denial of service.
Exploitation requires an application using the WebSocket client to connect to an attacker-controlled or compromised WebSocket endpoint.