THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-1526 (HIGH 7.5) — The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en

[NVD] CVE-2026-1526 (HIGH 7.5) — The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en

lownvdPublished 2026-03-12

CVE-2026-1526 CVSS: 7.5 HIGH Published: 2026-03-12T21:16:23.933

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A mali

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1526