PatchSiren cyber security CVE debrief
CVE-2026-2229 Nodejs CVE debrief
CVE-2026-2229 is a high-severity vulnerability in the undici WebSocket client, allowing for a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. A malicious server can respond with an out-of-range server_max_window_bits value, causing the client to crash. The vulnerability exists due to inadequate validation and exception handling in the isValidClientWindowBits function and createInflateRaw call. This issue affects undici versions prior to 6.24.0 and 7.24.0.
- Vendor
- Nodejs
- Product
- Undici
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-12
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-03-12
- Advisory updated
- 2026-09-04
Who should care
Developers and administrators using the undici WebSocket client in Node.js applications should prioritize patching this vulnerability to prevent potential denial-of-service attacks. Given the high CVSS score of 7.5, organizations should treat this issue with urgency. Affected versions include undici prior to 6.24.0 and 7.24.0.
Technical summary
The undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). The client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination. The vulnerability is caused by the isValidClientWindowBits() function only validating that the value contains ASCII digits, not that it falls within the valid range, and the createInflateRaw() call not being wrapped in a try-catch block.
Defensive priority
High priority should be given to patching CVE-2026-2229, as it allows for a denial-of-service attack with a CVSS score of 7.5. Immediate action is necessary to prevent potential disruptions to Node.js applications utilizing the undici WebSocket client.
Recommended defensive actions
- Update undici to version 6.24.0 or later, or 7.24.0 or later.
- Implement additional monitoring and logging to detect potential exploitation attempts.
- Review and update Node.js applications to ensure they are using patched versions of undici.
- Consider implementing compensating controls, such as rate limiting or IP blocking, to mitigate potential attacks.
- Verify that vendor advisories and security bulletins are being actively monitored and addressed.
Evidence notes
The CVE-2026-2229 vulnerability was publicly disclosed on March 12, 2026, and has a CVSS score of 7.5. The vulnerability affects undici versions prior to 6.24.0 and 7.24.0. Multiple sources, including NVD and vendor advisories, confirm the vulnerability and provide additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-2229 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-2229
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-2229 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2229
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://cna.openjsf.org/security-advisories.html
ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://datatracker.ietf.org/doc/html/rfc7692
ce714d77-add3-4f53-aff5-83d477b104bb - Technical Description
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8
ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://hackerone.com/reports/3487486
ce714d77-add3-4f53-aff5-83d477b104bb - Permissions Required
-
Source reference
Unverified legacy reference
URL: https://nodejs.org/api/zlib.html
ce714d77-add3-4f53-aff5-83d477b104bb - Technical Description
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13826
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:17789
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.