Uncaught Exception in undici - CVE-2026-19534
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uncaught exception in the undici WebSocket client opening handshake when processing a server response containing an unrequested Sec-WebSocket-Protocol header. A remote attacker can send a crafted WebSocket handshake response to cause a denial of service.
Exploitation requires an application to open a WebSocket connection to an attacker-controlled or compromised server, or to use a plaintext ws:// connection subject to a machine-in-the-middle.