SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19534

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The undici WebSocket client is vulnerable to a crash during the opening handshake when a server responds with an unexpected subprotocol, leading to an uncaught TypeError that terminates the Node.js process. This issue can be exploited remotely by any application that connects to a malicious or compromised WebSocket server, particularly over unencrypted connections. Organizations using affected versions of undici (6.7.0 to 6.28.1, 7.0.0 to 7.29.1, and 8.0.0 to 8.10.2) should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19534
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)