CVE-2026-22036
Vulnerability Summary
Timeline
Description
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.48%• Percentile: 41%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- chainguard•code-server
< 4.106.3-r2
- chainguard•gemini-cli
< 0.49.0-r4
- chainguard•jitsucom-jitsu-console
< 2.11.0-r12
- chainguard•jitsucom-jitsu-rotor
< 2.11.0-r12
- chainguard•kibana-8.19
< 8.19.10-r2
- chainguard•kibana-8.19-bitnami
< 8.19.10-r2
- chainguard•kibana-8.19-iamguarded
< 8.19.10-r2
- chainguard•kibana-9.0
< 9.0.8-r7
- chainguard•kibana-9.0-bitnami
< 9.0.8-r7
- chainguard•kibana-9.0-iamguarded
< 9.0.8-r7
- chainguard•kibana-9.1
< 9.1.10-r2
- chainguard•kibana-9.1-iamguarded
< 9.1.10-r2
- chainguard•kibana-9.2
< 9.2.3-r4
- chainguard•kibana-9.2-iamguarded
< 9.2.3-r4
- chainguard•langfuse-3-worker
< 3.146.0-r2
- chainguard•langfuse-fips-3-worker
< 3.147.0-r1
- chainguard•librechat
< 0.8.1-r5
- chainguard•renovate
< 42.92.4-r0 | < 42.94.1-r2
- wolfi•code-server
< 4.106.3-r2
- wolfi•jitsucom-jitsu-console
< 2.11.0-r12
- wolfi•jitsucom-jitsu-rotor
< 2.11.0-r12
- wolfi•langfuse-3-worker
< 3.146.0-r2
- wolfi•renovate
< 42.92.4-r0 | < 42.94.1-r2
- debian•node-undici
all | all | < 7.18.2+dfsg+~cs3.2.0-1
- nodejs•undici
< 6.23.0 | ≥ 7.0.0, < 7.18.2
- Npm•undici
≥ 7.0.0, < 7.18.2 | < 6.23.0
References (6)
- https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9
- https://github.com/nodejs/undici/commit/b04e3cbb569c1596f86c108e9b52c79d8475dcb3
- https://nvd.nist.gov/vuln/detail/CVE-2026-22036
- https://github.com/nodejs/undici
- https://security-tracker.debian.org/tracker/CVE-2026-22036
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22036.json