GHSA-rx4f-c7p8-82vq: Medium severity npm/undici vulnerability

Published Sep 29, 2026
·
Updated

Impact

undici's WebSocketStream crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls abort() on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with a TypeError, and the handler discards that promise. The unobserved rejection surfaces as an unhandledRejection and, under Node.js's default behavior, terminates the process.

A malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the WebSocketStream API and writing through a writer, which is the standard way to write.

All releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0.

Patches

Upgrade to undici v7.29.1 or v8.10.2.

Workarounds

No workaround is available.

Affected Software

2 affected componentsFixes available
npm/undici>=8.0.0<8.10.2
8.10.2
npm/undici>=7.0.0<7.29.1
7.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  3. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.10.2

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:10 PM
Data Sourced
via GitHub·06:10 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this denial-of-service risk?

Applications using undici's WebSocketStream API are affected if they write through a writer, which is the standard way to write. All undici releases starting with 7.0.0 are affected.

2

What does an attacker need to do to trigger the crash?

An attacker needs to control or compromise a WebSocket server that the client connects to, then terminate the connection without a close handshake. A TCP reset, proxy teardown, or protocol-violating frame can trigger the unclean close.

3

How can I determine whether my deployment is vulnerable?

Check whether the application depends on undici 7.0.0 or later and uses WebSocketStream with a writer. An affected client may terminate after an abrupt WebSocket connection closure because of an unhandled rejection.

4

What should I do if I cannot patch immediately?

No workaround is available. Upgrade undici to version 7.29.1 or 8.10.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203