undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade v8-12.4-develUpgrade nodejs24-libs-debuginfoUpgrade nodejs22-libsUpgrade nodejs24-npmUpgrade nodejs22-libs-debuginfoUpgrade nodejs24-libsUpgrade nodejs22-develUpgrade nodejs24-docsUpgrade nodejs22-debugsourceUpgrade nodejs22-npmUpgrade nodejs24-develUpgrade nodejs24-debuginfoUpgrade nodejs24-full-i18nUpgrade nodejs22-full-i18nUpgrade nodejs24Upgrade nodejs22-docsUpgrade v8-13.6-develUpgrade nodejs22Upgrade nodejs22-debuginfoUpgrade nodejs24-debugsource | Sep 30, 2026 | Sep 4, 2026 |
| Redhat_linux | — | Upgrade nodejs24-debuginfoUpgrade nodejs-libs-debuginfoUpgrade v8-13.6-develUpgrade nodejs24Upgrade nodejs-packaging-bundlerUpgrade v8-12.4-develUpgrade nodejs-debuginfoUpgrade nodejs24-full-i18nUpgrade nodejs-develUpgrade npmUpgrade nodejs24-libsUpgrade nodejs-debugsourceUpgrade nodejs22-debuginfoUpgrade nodejs24-libs-debuginfoUpgrade nodejsUpgrade nodejs-nodemonUpgrade nodejs24-npmUpgrade nodejs-libsUpgrade nodejs-npmUpgrade nodejs24-docsUpgrade nodejs24-develNo solution existsUpgrade nodejs-full-i18nUpgrade nodejs22-debugsourceUpgrade nodejs-packagingUpgrade nodejs24-debugsourceUpgrade nodejs-docs | Sep 7, 2026 | Sep 4, 2026 |
| Rocky_linux | — | Upgrade npmUpgrade nodejs24-full-i18nUpgrade nodejs24-libs-debuginfoUpgrade nodejs24-debuginfoUpgrade nodejs-debuginfoUpgrade nodejs-npmUpgrade v8-12.4-develUpgrade nodejs22-debuginfoUpgrade nodejs24-develUpgrade nodejs24-libsUpgrade v8-13.6-develUpgrade nodejs24Upgrade nodejsUpgrade nodejs-debugsourceUpgrade nodejs22-debugsourceUpgrade nodejs-libs-debuginfoUpgrade nodejs24-debugsourceUpgrade nodejs-libsUpgrade nodejs-develUpgrade nodejs-full-i18n | Oct 5, 2026 | Oct 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub