CVE-2026-85024

Aliases:DEBIAN-CVE-2026-85024UBUNTU-CVE-2026-85024
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 04 Sept 2026, 16:20
Last modified:04 Sept 2026, 19:30

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v3.1 (cve.org)
EPSS Score
0.26% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Sept 2026, 16:20
Published
Vulnerability first disclosed
04 Sept 2026, 19:30
Last Modified
Vulnerability information updated

Description

undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.26% Percentile: 17%

Techniques & Countermeasures

  • CWE-248Uncaught Exception

    An exception is thrown from a function, but it is not caught.

Affected Systems

  • debiannode-undici

    all | all | all | < 8.10.2+dfsg+~cs3.2.2-1

  • ubuntunode-undici

    all | all

  • nodejsundici

    ≥ 6.25.0, < 6.28.1 | ≥ 7.28.0, < 7.29.1 | ≥ 8.1.0, < 8.10.2

  • undiciundici

    ≥ 6.25.0, < 6.28.1 | ≥ 7.28.0, < 7.29.1 | ≥ 8.1.0, < 8.10.2

References (5)