CVE-2026-2229

Aliases:GHSA-v9p9-hfj2-hcw8DEBIAN-CVE-2026-2229CGA-3vvv-p294-c7h8CGA-43rp-vvg9-44xwCGA-4jqc-vwrm-rg7xCGA-6685-m228-rgffCGA-9m5f-hmrg-cpq2CGA-cgqg-9mgr-hg4mCGA-ch47-xmx6-3hq7CGA-f2rf-232q-fgr3CGA-p49p-v5wh-5qwjCGA-26xc-x238-7hg5CGA-29qw-cqcr-92r4CGA-35c4-4mr2-xvvvCGA-38x9-m43v-j3g3CGA-52pj-863v-w3h6CGA-53wj-6h2x-57vjCGA-628f-8mqm-6gc4CGA-6mw8-32hj-mjrhCGA-6vh8-jq8m-c5p9CGA-747f-hpj7-wvcpCGA-79vv-xx8c-cr3gCGA-7c7p-2jh2-fhgjCGA-7h5f-m9vg-h7fgCGA-7hvm-6mgx-5x7vCGA-7jm6-mwpp-5w6jCGA-7m48-5r2x-mvj9CGA-83f3-wjrh-53mcCGA-8cp5-hr74-3g3mCGA-8gc2-f7fx-c29jCGA-8jrv-rr57-xwg8CGA-8q55-3p63-h7mhCGA-9crh-27gf-7rjrCGA-9r2h-668x-gjgmCGA-9r96-734g-wc92CGA-9xc5-w9hv-49fqCGA-c8mj-rwqh-xwv4CGA-fq6h-c7xr-2fc6CGA-gccc-9348-w245CGA-gv38-vpf5-5897CGA-h86g-66qg-cr2hCGA-hcqr-hc8c-q87rCGA-j38r-57cx-45vqCGA-m69v-r2x2-363jCGA-mjp4-x2fg-8rghCGA-mxj4-63hj-2h82CGA-p478-vwh2-x92jCGA-q76v-p397-xrrwCGA-qc97-8983-x5f4CGA-qmwp-vf4w-2ffjCGA-qqwj-6fw8-6ch2CGA-rqr6-2jwr-5r6hCGA-rvj6-w26x-prr4CGA-v3jf-crfj-jfh7CGA-vm2q-6cf8-2wfpCGA-vvg5-q5hj-7xcfCGA-wp7c-8c79-crmfCGA-wrj3-xx8m-8fx5CGA-wv77-7rq6-hg2pCGA-wvw9-8237-j33h
Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 12 Mar 2026, 20:27
Last modified:14 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.87% LOW
1% probability +0.70%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Mar 2026, 20:27
Published
Vulnerability first disclosed
14 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). When the server subsequently sends a compressed frame, the client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination. The vulnerability exists because: * The isValidClientWindowBits() function only validates that the value contains ASCII digits, not that it falls within the valid range 8-15 * The createInflateRaw() call is not wrapped in a try-catch block * The resulting exception propagates up through the call stack and crashes the Node.js process

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.87% Percentile: 57%

Techniques & Countermeasures

  • CWE-248Uncaught Exception

    An exception is thrown from a function, but it is not caught.

  • CWE-1284Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Affected Systems

  • chainguardcode-server

    < 4.110.1-r2

  • chainguardgemini-cli

    < 0.49.0-r4

  • chainguardjitsucom-jitsu-console

    < 2.11.0-r17

  • chainguardjitsucom-jitsu-rotor

    < 2.11.0-r17

  • chainguardkibana-8.17

    < 8.17.10-r13

  • chainguardkibana-8.17-bitnami

    < 8.17.10-r13

  • chainguardkibana-8.17-iamguarded

    < 8.17.10-r13

  • chainguardkibana-8.18

    < 8.18.8-r11

  • chainguardkibana-8.18-bitnami

    < 8.18.8-r11

  • chainguardkibana-8.18-iamguarded

    < 8.18.8-r11

  • chainguardkibana-8.19

    < 8.19.13-r4

  • chainguardkibana-8.19-bitnami

    < 8.19.13-r4

  • chainguardkibana-8.19-iamguarded

    < 8.19.13-r4

  • chainguardkibana-9.0

    < 9.0.8-r14

  • chainguardkibana-9.0-bitnami

    < 9.0.8-r14

  • chainguardkibana-9.0-iamguarded

    < 9.0.8-r14

  • chainguardkibana-9.1

    < 9.1.10-r7

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r7

  • chainguardkibana-9.2

    < 9.2.7-r0 | < 9.2.6-r3

  • chainguardkibana-9.2-iamguarded

    < 9.2.6-r3

  • chainguardkibana-9.3

    < 9.3.2-r0

  • chainguardkibana-9.3-iamguarded

    < 9.3.2-r0 | < 9.3.1-r2

  • chainguardlangfuse-3-worker

    < 3.179.1-r1

  • chainguardlangfuse-fips-3-worker

    < 3.179.1-r1

  • chainguardlangfuse-fips-3.152-worker

    all

  • chainguardlibrechat

    < 0.8.4-r3

  • chainguardpelias-api

    < 7.6.0-r4

  • chainguardrenovate

    < 43.84.0-r1

  • wolficode-server

    < 4.110.1-r2

  • wolfijitsucom-jitsu-console

    < 2.11.0-r17

  • wolfijitsucom-jitsu-rotor

    < 2.11.0-r17

  • wolfilangfuse-3-worker

    < 3.179.1-r1

  • wolfirenovate

    < 43.84.0-r1

  • debiannode-undici

    all | all | < 7.24.5+dfsg+~cs3.2.0-1

  • nodejsundici

    < 6.24.0 | ≥ 7.0.0, < 7.24.0

  • Npmundici

    < 6.24.0 | ≥ 7.0.0, < 7.24.0

  • undiciundici

    < 6.24.0; 7.0.0 < 7.24.0

References (29)