---
cve: "CVE-2026-2229"
severity: "HIGH"
cvss: 7.5
epss: "0.9%"
vendor: "undici"
kev: false
exploited: false
published: "2026-03-12 21:16:25"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T06:55:39+02:00"
---

# CVE-2026-2229

> 7.5 HIGH · 🧪 PoC

## Beschreibung

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). When the server subsequently sends a compressed frame, the client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination.

The vulnerability exists because:

  *  The isValidClientWindowBits() function only validates that the value contains ASCII digits, not that it falls within the valid range 8-15
  *  The createInflateRaw() call is not wrapped in a try-catch block
  *  The resulting exception propagates up through the call stack and crashes the Node.js process

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 8873c947271faf1ebc455bdc6158ecbc022ecfa9 (Commit)
- 07a39067a0485c1953196f500d945fe09378a176 (Commit)

## Referenzen

- <https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8>
- <https://hackerone.com/reports/3487486>
- <https://cna.openjsf.org/security-advisories.html>
- <https://datatracker.ietf.org/doc/html/rfc7692>
- <https://nodejs.org/api/zlib.html#class-zlibinflateraw>
- <https://access.redhat.com/errata/RHSA-2026:13826>
- <https://access.redhat.com/errata/RHSA-2026:17789>
- <https://access.redhat.com/errata/RHSA-2026:21772>
- <https://access.redhat.com/errata/RHSA-2026:21931>
- <https://access.redhat.com/errata/RHSA-2026:34342>
- <https://access.redhat.com/errata/RHSA-2026:56431>
- <https://access.redhat.com/errata/RHSA-2026:5807>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-2229) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
