PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-2229 Nodejs CVE debrief

CVE-2026-2229 is a high-severity vulnerability in the undici WebSocket client, allowing for a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. A malicious server can respond with an out-of-range server_max_window_bits value, causing the client to crash. The vulnerability exists due to inadequate validation and exception handling in the isValidClientWindowBits function and createInflateRaw call. This issue affects undici versions prior to 6.24.0 and 7.24.0.

Vendor
Nodejs
Product
Undici
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-12
Original CVE updated
2026-09-04
Advisory published
2026-03-12
Advisory updated
2026-09-04

Who should care

Developers and administrators using the undici WebSocket client in Node.js applications should prioritize patching this vulnerability to prevent potential denial-of-service attacks. Given the high CVSS score of 7.5, organizations should treat this issue with urgency. Affected versions include undici prior to 6.24.0 and 7.24.0.

Technical summary

The undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). The client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination. The vulnerability is caused by the isValidClientWindowBits() function only validating that the value contains ASCII digits, not that it falls within the valid range, and the createInflateRaw() call not being wrapped in a try-catch block.

Defensive priority

High priority should be given to patching CVE-2026-2229, as it allows for a denial-of-service attack with a CVSS score of 7.5. Immediate action is necessary to prevent potential disruptions to Node.js applications utilizing the undici WebSocket client.

Recommended defensive actions

  • Update undici to version 6.24.0 or later, or 7.24.0 or later.
  • Implement additional monitoring and logging to detect potential exploitation attempts.
  • Review and update Node.js applications to ensure they are using patched versions of undici.
  • Consider implementing compensating controls, such as rate limiting or IP blocking, to mitigate potential attacks.
  • Verify that vendor advisories and security bulletins are being actively monitored and addressed.

Evidence notes

The CVE-2026-2229 vulnerability was publicly disclosed on March 12, 2026, and has a CVSS score of 7.5. The vulnerability affects undici versions prior to 6.24.0 and 7.24.0. Multiple sources, including NVD and vendor advisories, confirm the vulnerability and provide additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-2229 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-2229

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-2229 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2229

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://cna.openjsf.org/security-advisories.html

    ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://datatracker.ietf.org/doc/html/rfc7692

    ce714d77-add3-4f53-aff5-83d477b104bb - Technical Description

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8

    ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://hackerone.com/reports/3487486

    ce714d77-add3-4f53-aff5-83d477b104bb - Permissions Required

  • Source reference

    Unverified legacy reference

    URL: https://nodejs.org/api/zlib.html

    ce714d77-add3-4f53-aff5-83d477b104bb - Technical Description

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:13826

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:17789

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.