CVE-2026-12151

Aliases:GHSA-vxpw-j846-p89qDEBIAN-CVE-2026-12151CGA-2fjv-j3vc-v42vCGA-2xjh-pvqm-q6fqCGA-32wv-xpjw-59rwCGA-4h2f-p7c3-h2prCGA-5m87-f6gg-3v3hCGA-5qq3-xqv9-p39wCGA-6pp5-3hgf-pf39CGA-7g5h-v9m4-q2r2CGA-9j5m-pg63-wp3cCGA-j7wm-499f-j6fjCGA-jx7w-46hv-33crCGA-m98c-2392-xfxqCGA-mm9f-44ph-hvw8CGA-mw7p-pfw7-29h4CGA-27g6-j8q4-2vw7CGA-3g69-jhrm-c9mqCGA-3qxm-hxm7-ph8jCGA-4c2f-fgvm-mpm6CGA-4g73-383v-j849CGA-4grj-pfjq-9r2wCGA-4m7c-p45c-669rCGA-58mh-q9q6-36c8CGA-62cv-j5vm-hhf6CGA-6562-rwq2-qrj8CGA-6x78-rqxv-pmm3CGA-759j-8v7x-6w8vCGA-7657-wq2r-9qf4CGA-7g69-6r9j-pfqhCGA-7hc7-mcv4-6h58CGA-7jhf-8x24-h6qwCGA-85hr-2ff4-5f56CGA-8c3h-34w9-8hj2CGA-9xj2-2gqh-f78jCGA-c3h9-mf5w-9cjwCGA-cch6-3688-q4c7CGA-f7c9-xvgc-7x26CGA-f8jf-9g98-2fxwCGA-g55f-qf52-gx7cCGA-hmh3-3r66-f3jpCGA-j9vr-898m-q9fgCGA-jjxh-qgjj-ggjqCGA-mc58-7hg6-vjw5CGA-mvxj-5w4g-rgxrCGA-p526-7436-9xxmCGA-p78q-jcf2-p68rCGA-pvhr-p69m-xcjxCGA-q2xg-wvqf-7m8cCGA-q5j6-55f2-fxm9CGA-r8m3-vggv-7226CGA-r9m6-fg56-3pghCGA-rxf3-c896-v7jxCGA-v478-rqq6-vxmwCGA-v9h6-g245-94f2CGA-vffw-cwr3-5xr3CGA-vh7x-qcq6-j5fhCGA-vhfw-w45g-6q2gCGA-vr94-p9hv-5c3rCGA-vw8f-3f2x-p776CGA-w762-wmqj-6j26CGA-wc3q-c3x4-428mCGA-x4c4-q7h4-pv9fCGA-xc3v-mx5f-69m9CGA-4q28-fw5q-8wrrCGA-fxc2-chgg-5w4gCGA-hc99-v4v6-qvf7CGA-8c66-44cc-xf7hCGA-hqf5-c2m9-gvfhCGA-2qv9-2fjm-48p8CGA-9q35-f35g-5rx2CGA-hqxw-v822-96r5CGA-r5gh-mwmp-x46vCGA-8mpj-qfq6-j66p
Modified
Published: 17 Jun 2026, 16:05
Last modified:11 Sept 2026, 12:08

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.79% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jun 2026, 16:05
Published
Vulnerability first disclosed
11 Sept 2026, 12:08
Last Modified
Vulnerability information updated

Description

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.79% Percentile: 55%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardactions-runner

    < 2.335.1-r1

  • chainguardcode-server

    < 4.125.0-r2

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgemini-cli

    < 0.49.0-r4

  • chainguardharaka

    < 3.3.1-r1

  • chainguardkibana-8.19

    < 8.19.16-r6

  • chainguardkibana-8.19-bitnami

    < 8.19.16-r6

  • chainguardkibana-8.19-iamguarded

    < 8.19.16-r6

  • chainguardkibana-9.1

    < 9.1.10-r21

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r21

  • chainguardkibana-9.2

    < 9.2.8-r9

  • chainguardkibana-9.2-iamguarded

    < 9.2.8-r9

  • chainguardkibana-9.3

    < 9.3.5-r4

  • chainguardkibana-9.3-iamguarded

    < 9.3.5-r4

  • chainguardkibana-9.4

    < 9.4.2-r5

  • chainguardkibana-9.4-iamguarded

    < 9.4.2-r5

  • chainguardnode-gyp

    < 13.0.0-r1

  • chainguardnpm

    < 11.17.0-r1

  • chainguardpelias-api

    < 7.8.0-r4

  • chainguardprism

    < 5.15.11-r3

  • chainguardpy3.10-captum

    < 0.9.0-r1

  • chainguardpy3.11-captum

    < 0.9.0-r1

  • chainguardpy3.12-captum

    < 0.9.0-r1

  • chainguardpy3.13-captum

    < 0.9.0-r1

  • chainguardrenovate

    < 43.249.5-r2 | < 43.247.0-r0

  • chainguardsaf

    < 1.6.0-r2

  • chainguardvitess-24

    < 24.0.2-r1

  • chainguardvitess-24-compat

    < 24.0.3-r7

  • wolficode-server

    < 4.125.0-r2

  • wolfinode-gyp

    < 13.0.0-r1

  • wolfinpm

    < 11.17.0-r1

  • wolfiprism

    < 5.15.11-r3

  • wolfirenovate

    < 43.249.5-r2 | < 43.247.0-r0

  • wolfisaf

    < 1.6.0-r2

  • wolfivitess-24

    < 24.0.2-r1

  • wolfivitess-24-compat

    < 24.0.3-r7

  • debiannode-undici

    all | all | < 8.5.0+dfsg+~cs3.2.0-1

  • nodejsundici

    ≥ 6.17.0, < 6.27.0 | ≥ 7.0.0, < 7.28.0 | ≥ 8.0.0, < 8.5.0

  • Npmundici

    < 6.27.0 | ≥ 7.0.0, < 7.28.0 | ≥ 8.0.0, < 8.5.0

  • undiciundici

    < 6.26.0 | ≥ 7.0.0, < 7.28.0 | ≥ 8.0.0, < 8.5.0

References (35)