Upstream information
CVE-2026-1528 at MITRE
Description
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
CVSS v3 Scores
| CVSS detail | CNA (openjs) |
| Base Score | 7.5 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | None |
| Integrity Impact | None |
| Availability Impact | High |
| CVSSv3 Version | 3.1 |
No SUSE Bugzilla entries cross referenced.
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| SUSE Liberty Linux 10 | nodejs >= 1:22.22.2-1.el10_1
nodejs-devel >= 1:22.22.2-1.el10_1
nodejs-docs >= 1:22.22.2-1.el10_1
nodejs-full-i18n >= 1:22.22.2-1.el10_1
nodejs-libs >= 1:22.22.2-1.el10_1
nodejs-npm >= 1:10.9.7-1.22.22.2.1.el10_1
nodejs24 >= 1:24.14.1-2.el10_1
nodejs24-devel >= 1:24.14.1-2.el10_1
nodejs24-docs >= 1:24.14.1-2.el10_1
nodejs24-full-i18n >= 1:24.14.1-2.el10_1
nodejs24-libs >= 1:24.14.1-2.el10_1
nodejs24-npm >= 1:11.11.0-1.24.14.1.2.el10_1
| Patchnames: RHSA-2026:7080 (x86_64) RHSA-2026:7675 (x86_64) |
| SUSE Liberty Linux 8 | nodejs >= 1:24.14.1-2.module+el8.10.0+24190+49a46c75
nodejs-devel >= 1:24.14.1-2.module+el8.10.0+24190+49a46c75
nodejs-docs >= 1:24.14.1-2.module+el8.10.0+24190+49a46c75
nodejs-full-i18n >= 1:24.14.1-2.module+el8.10.0+24190+49a46c75
nodejs-libs >= 1:24.14.1-2.module+el8.10.0+24190+49a46c75
nodejs-nodemon >= 3.0.3-1.module+el8.10.0+24190+49a46c75
nodejs-packaging >= 2021.06-6.module+el8.10.0+24190+49a46c75
nodejs-packaging-bundler >= 2021.06-6.module+el8.10.0+24190+49a46c75
npm >= 1:11.11.0-1.24.14.1.2.module+el8.10.0+24190+49a46c75
v8-12.4-devel >= 3:12.4.254.21-1.22.22.2.1.module+el8.10.0+24148+847b6786
v8-13.6-devel >= 3:13.6.233.17-1.24.14.1.2.module+el8.10.0+24190+49a46c75
| Patchnames: RHSA-2026:7123 (x86_64) RHSA-2026:7670 (x86_64) |
| SUSE Liberty Linux 9.6 EMS | nodejs >= 1:22.22.2-1.module+el9.6.0+24196+39669d4e
nodejs-devel >= 1:22.22.2-1.module+el9.6.0+24196+39669d4e
nodejs-docs >= 1:22.22.2-1.module+el9.6.0+24196+39669d4e
nodejs-full-i18n >= 1:22.22.2-1.module+el9.6.0+24196+39669d4e
nodejs-libs >= 1:22.22.2-1.module+el9.6.0+24196+39669d4e
nodejs-nodemon >= 3.0.1-1.module+el9.6.0+23473+45664c2d
nodejs-packaging >= 2021.06-4.module+el9.6.0+23473+45664c2d
nodejs-packaging-bundler >= 2021.06-4.module+el9.6.0+23473+45664c2d
npm >= 1:10.9.7-1.22.22.2.1.module+el9.6.0+24196+39669d4e
v8-12.4-devel >= 3:12.4.254.21-1.22.22.2.1.module+el9.6.0+24196+39669d4e
| Patchnames: RHSA-2026:7983 (x86_64) |
| SUSE Liberty Linux 9 | nodejs >= 1:24.14.1-2.module+el9.7.0+24166+51c9666b
nodejs-devel >= 1:24.14.1-2.module+el9.7.0+24166+51c9666b
nodejs-docs >= 1:24.14.1-2.module+el9.7.0+24166+51c9666b
nodejs-full-i18n >= 1:24.14.1-2.module+el9.7.0+24166+51c9666b
nodejs-libs >= 1:24.14.1-2.module+el9.7.0+24166+51c9666b
nodejs-nodemon >= 3.0.3-3.module+el9.7.0+24166+51c9666b
nodejs-packaging >= 2021.06-6.module+el9.7.0+24166+51c9666b
nodejs-packaging-bundler >= 2021.06-6.module+el9.7.0+24166+51c9666b
npm >= 1:11.11.0-1.24.14.1.2.module+el9.7.0+24166+51c9666b
v8-12.4-devel >= 3:12.4.254.21-1.22.22.2.1.module+el9.7.0+24157+8ddb2461
v8-13.6-devel >= 3:13.6.233.17-1.24.14.1.2.module+el9.7.0+24166+51c9666b
| Patchnames: RHSA-2026:7302 (x86_64) RHSA-2026:7350 (x86_64) |
SUSE Timeline for this CVE
CVE page created: Fri Mar 13 00:03:34 2026
CVE page last modified: Thu Oct 8 17:32:55 2026