THREAT OPS › Threat News › [NVD] CVE-2026-12151 (HIGH 7.5) — Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and
[NVD] CVE-2026-12151 (HIGH 7.5) — Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and
CVE-2026-12151 CVSS: 7.5 HIGH Published: 2026-06-17T17:16:42.370
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbo
Indicators of compromise
- CVE-2026-12151cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12151