CVE-2026-85014
Received Received - Intake

WebSocketStream Process Crash in Undici

Vulnerability report for CVE-2026-85014, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: openjs

Description

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
undici undici From 7.0.0 (inc) to 7.29.1 (inc)
undici undici From 8.0.0 (inc) to 8.10.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves undici's experimental WebSocketStream client crashing the entire Node.js process when a remote peer closes the TCP connection without completing the WebSocket close handshake. The issue occurs because the internal socket-close handler unconditionally aborts the writable stream, which violates the WHATWG Streams standard. If the writable stream is locked, aborting it returns a rejected promise with a TypeError, but since the application holds a writer on the stream, the rejection goes unobserved. Node.js then terminates the process due to the unhandled rejection.

Detection Guidance

This vulnerability is specific to undici library versions between 7.0.0-7.29.0 and 8.0.0-8.10.1. Check your installed version with 'npm list undici' or 'node -e "console.log(require('undici/package.json').version)"'. Monitor Node.js process crashes after abrupt TCP disconnections from WebSocket servers.

Impact Analysis

An attacker could exploit this by abruptly disconnecting from a vulnerable client application, causing the entire Node.js process to crash. This could lead to denial of service, disrupting services relying on the application. The attack requires no authentication and can be executed by any untrusted server.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing unexpected application crashes, potentially leading to data processing interruptions or loss of availability. Unplanned terminations may violate requirements for continuous data access and system reliability under these regulations.

Mitigation Strategies

Upgrade undici to version 7.29.1 or 8.10.2 or later immediately. Update package.json dependencies to enforce these versions. Restart affected Node.js applications after updating.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85014. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart