THREAT OPS › Threat News › [NVD] CVE-2026-1526 (HIGH 7.5) — The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en
[NVD] CVE-2026-1526 (HIGH 7.5) — The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en
CVE-2026-1526 CVSS: 7.5 HIGH Published: 2026-03-12T21:16:23.933
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A mali
Indicators of compromise
- CVE-2026-1526cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1526