{"id":"AZL-91191","summary":"CVE-2026-12151 affecting package nodejs for versions less than 24.18.1-1","details":"Impact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\nAll releases starting at undici 6.17.0 are affected.\n\nPatches: Upgrade to undici \u003e= 6.26.0, \u003e= 7.28.0, or \u003e= 8.5.0. Workarounds:\nNo workaround is available. The fix must be applied through an upgrade.","modified":"2026-08-31T05:26:27Z","published":"2026-06-17T17:16:42Z","upstream":["CVE-2026-12151"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12151"}],"affected":[{"package":{"name":"nodejs","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/nodejs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.18.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91191.json"}}],"schema_version":"1.9.0"}