CVE-2026-22036

Aliases:GHSA-g9mf-h72j-4rw9DEBIAN-CVE-2026-22036CGA-6f7j-jf4c-849pCGA-92g2-4542-6fv6CGA-fqw6-h2gg-2433CGA-gpw7-xhjg-894wCGA-28j2-43w4-r6qfCGA-2h47-w2x9-76gmCGA-2p7p-ph27-pvjfCGA-2wmc-wm73-26rgCGA-33pv-3v3j-7pf4CGA-34hh-23ph-393pCGA-36x5-cxhr-3wmgCGA-3r5r-cc7x-r7w5CGA-3x38-fhvj-hcqxCGA-44v5-f86c-4f9hCGA-4vxq-vh7g-jw5xCGA-4x6q-vfj5-p48jCGA-57rh-w893-p6f9CGA-5g76-v49c-342gCGA-5hg8-5gjp-x5rfCGA-5j6m-36q7-5xx9CGA-5q57-rr9f-p89hCGA-7288-77r7-w9f3CGA-9vqq-86fp-c8fhCGA-c38j-hj4j-87f2CGA-chwf-h4pw-3p6wCGA-cqvr-mmhv-78r2CGA-f8p4-mc53-536pCGA-f8qr-jc9j-f36wCGA-jxj4-qfpq-vg8xCGA-mvgv-gc84-45qpCGA-p4h9-3xmf-qjj4CGA-qxwf-q2rf-6w46CGA-r3c6-rqcp-542cCGA-rpwf-39j3-8pj4CGA-rqr5-vq4g-8pc9CGA-rxjx-872g-j9v2CGA-rxqj-v85g-4rp2CGA-v29g-98j5-rgpcCGA-v8m5-gg92-w5x8CGA-vmhr-g96m-xffgCGA-vpvm-73wh-7x7rCGA-vxrq-hw4f-954pCGA-wfj5-f53g-h9f8CGA-x3jv-79h2-3426CGA-x7vc-gvwh-g8j9CGA-xg7m-m974-xg44
Modified
Published: 14 Jan 2026, 19:07
Last modified:22 Jan 2026, 20:17

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.48% LOW
0% probability +0.46%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jan 2026, 19:07
Published
Vulnerability first disclosed
22 Jan 2026, 20:17
Last Modified
Vulnerability information updated

Description

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.48% Percentile: 41%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardcode-server

    < 4.106.3-r2

  • chainguardgemini-cli

    < 0.49.0-r4

  • chainguardjitsucom-jitsu-console

    < 2.11.0-r12

  • chainguardjitsucom-jitsu-rotor

    < 2.11.0-r12

  • chainguardkibana-8.19

    < 8.19.10-r2

  • chainguardkibana-8.19-bitnami

    < 8.19.10-r2

  • chainguardkibana-8.19-iamguarded

    < 8.19.10-r2

  • chainguardkibana-9.0

    < 9.0.8-r7

  • chainguardkibana-9.0-bitnami

    < 9.0.8-r7

  • chainguardkibana-9.0-iamguarded

    < 9.0.8-r7

  • chainguardkibana-9.1

    < 9.1.10-r2

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r2

  • chainguardkibana-9.2

    < 9.2.3-r4

  • chainguardkibana-9.2-iamguarded

    < 9.2.3-r4

  • chainguardlangfuse-3-worker

    < 3.146.0-r2

  • chainguardlangfuse-fips-3-worker

    < 3.147.0-r1

  • chainguardlibrechat

    < 0.8.1-r5

  • chainguardrenovate

    < 42.92.4-r0 | < 42.94.1-r2

  • wolficode-server

    < 4.106.3-r2

  • wolfijitsucom-jitsu-console

    < 2.11.0-r12

  • wolfijitsucom-jitsu-rotor

    < 2.11.0-r12

  • wolfilangfuse-3-worker

    < 3.146.0-r2

  • wolfirenovate

    < 42.92.4-r0 | < 42.94.1-r2

  • debiannode-undici

    all | all | < 7.18.2+dfsg+~cs3.2.0-1

  • nodejsundici

    < 6.23.0 | ≥ 7.0.0, < 7.18.2

  • Npmundici

    ≥ 7.0.0, < 7.18.2 | < 6.23.0

References (6)