CVE detail
CVE-2026-12151
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
19 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:41947access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:41929access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:39868access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:36621access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:39246access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:38236access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:38009access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 17, 2026, 5:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2489980bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/security/cve/CVE-2026-12151access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:36820access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:36754access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:35892access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:35891access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:35842access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:35841access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM - https://access.redhat.com/errata/RHSA-2026:34342access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 5:16 PM No excerpt available.
Exploitgithub.comJun 17, 2026, 5:16 PM- https://cna.openjsf.org/security-advisories.htmlcna.openjsf.org
No excerpt available.
Vendor Advisorycna.openjsf.orgJun 17, 2026, 5:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-9675CVSS 7.5 · High
Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server ca…
- CVE-2026-54609CVSS 8.6 · High
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the…
- CVE-2026-17501CVSS 6.9 · Medium
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-t…
- CVE-2026-14257CVSS 7.5 · High
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but…
- CVE-2026-55831CVSS 7.5 · High
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-dec…
- CVE-2026-53596CVSS 5.3 · Medium
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on t…