GHSA-3wwx-pv8p-q78v: Medium severity npm/undici vulnerability
Impact
undici's WebSocket client (including Node.js's bundled globalThis.WebSocket) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. In lib/web/websocket/permessage-deflate.js, the size-limit cleanup calls removeAllListeners() on the internal zlib InflateRaw, removing its error listener, but leaves the stream running. The inflater then emits a ZDATAERROR with no listener attached, which Node.js treats as a fatal unhandled error event and terminates the process. Application error/close handlers on the public WebSocket cannot observe or prevent this, because the failing object is the internal InflateRaw.
A malicious or compromised WebSocket server can crash a client with a single connection, unauthenticated and without any application mistake. The attack is asymmetric (about 130 KB on the wire expands past the limit) and can be repeated on reconnect (crash loop).
Affected applications are those using the undici WebSocket client (new WebSocket(...)) or Node.js's bundled globalThis.WebSocket that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.
Patches
Upgrade to undici v6.28.1, v7.29.1 or v8.10.2.
Workarounds
No workaround is available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 6.28.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 6.28.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.10.2
Event History
Frequently Asked Questions
Which applications are exposed to this crash?
Applications using undici's WebSocket client through new WebSocket(...) or Node.js's bundled globalThis.WebSocket are exposed when they connect to a malicious or compromised WebSocket peer capable of sending the crafted compressed message.
Does exploitation require authentication, user interaction, or an application coding mistake?
No. A remote WebSocket peer can trigger the crash over a single connection without authentication, user interaction, or an application mistake.
Can public WebSocket error or close handlers prevent the process termination?
No. The unhandled error is emitted by an internal zlib InflateRaw object after its error listener is removed, so application handlers on the public WebSocket cannot observe or prevent it.
What operational impact should be expected if a client automatically reconnects?
The attack can be repeated whenever the client reconnects, potentially producing a crash loop. The crafted payload is asymmetric: roughly 130 KB sent on the wire can expand past the decompressed-payload limit.