REDHAT-BUG-2489980: High severity npm/undici vulnerability
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.
Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.
All releases starting at undici 6.17.0 are affected.
Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
undici WebSocket client (undici)to a version that resolves this vulnerability.Fixed in 6.26.0 - Upgrade
Upgrade
undici WebSocket client (undici)to a version that resolves this vulnerability.Fixed in 7.28.0 - Upgrade
Upgrade
undici WebSocket client (undici)to a version that resolves this vulnerability.Fixed in 8.5.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2489980?
The severity of REDHAT-BUG-2489980 is classified as high with a score of 7.
What impact does REDHAT-BUG-2489980 have?
REDHAT-BUG-2489980 allows a malicious WebSocket server to potentially overload the client due to an unregulated number of fragments in a message.
How do I fix REDHAT-BUG-2489980?
To fix REDHAT-BUG-2489980, update the undici WebSocket client to the latest version where the vulnerability has been addressed.
What software is affected by REDHAT-BUG-2489980?
The vulnerable software affected by REDHAT-BUG-2489980 is npm/undici.
Can REDHAT-BUG-2489980 be exploited remotely?
Yes, REDHAT-BUG-2489980 can be exploited remotely by a malicious WebSocket server.