{"id":"GHSA-rx4f-c7p8-82vq","summary":"undici vulnerable to Denial of Service via WebSocketStream unclean close","details":"## Impact\n\nundici's `WebSocketStream` crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls `abort()` on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with a `TypeError`, and the handler discards that promise. The unobserved rejection surfaces as an `unhandledRejection` and, under Node.js's default behavior, terminates the process.\n\nA malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the `WebSocketStream` API and writing through a writer, which is the standard way to write.\n\nAll releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0.\n\n## Patches\n\nUpgrade to undici v7.29.1 or v8.10.2.\n\n## Workarounds\n\nNo workaround is available.","aliases":["CVE-2026-85014"],"modified":"2026-09-29T18:15:04.711653428Z","published":"2026-09-29T18:10:32Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-29T18:10:32Z","nvd_published_at":"2026-09-04T17:17:02Z","cwe_ids":["CWE-248","CWE-754"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85014"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/nodejs/undici"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v7.29.1"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v8.10.2"}],"affected":[{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.29.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rx4f-c7p8-82vq/GHSA-rx4f-c7p8-82vq.json"}},{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rx4f-c7p8-82vq/GHSA-rx4f-c7p8-82vq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}