CVE-2026-1526 is a denial-of-service vulnerability affecting the undici WebSocket client used in Node.js, stemming from unbounded memory consumption during permessage-deflate decompression. A malicious WebSocket server can exploit this by sending a small, compressed "decompression bomb" frame that expands excessively in memory, causing the Node.js process to crash or become unresponsive. Rated 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), this attack is network-based with low complexity and requires no user interaction. Currently, there is no evidence of active exploitation, public exploit code availability (e.g., Metasploit, Nuclei), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.24.0CPE matchmatch criteria | cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | ||
>= 7.0.0, < 7.24.0CPE matchmatch criteria | cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.