Disclosure summary
### Impact The undici WebSocket client throws an uncaught `TypeError` during the opening handshake when a server's `101` response includes a `Sec-WebSocket-Protocol` header that the client never requested. The throw occurs in a `queueMicrotask` callback with no surrounding `try`/`catch`, so it propagates as an uncaught exception and terminates the Node.js process. This is a remote, unauthenticated denial of service against any application that opens a WebSocket to an attacker controlled or compromised server, or over a plaintext `ws://` connection subject to a machine-in-the-middle. It affects the default `new WebSocket(url)` usage, where no subprotocol is requested. Per RFC 6455 section 4.1, an unrequested subprotocol must fail the connection, not crash it. All releases starting at undici 6.7.0 are affected. ### Patches Upgrade to undici 6.28.1, 7.29.1, or 8.10.2. ### Workarounds No workaround is available. The fix must be applied through an upgrade.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-rfgv-xxqx-mfg5
Open original source · Updated Sep 29, 2026
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | undici | >= 6.7.0, < 6.28.1 | 6.28.1 |
| npm | undici | >= 7.0.0, < 7.29.1 | 7.29.1 |
| npm | undici | >= 8.0.0, < 8.10.2 | 8.10.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T14:21:33-04:00
MODIFIED 2026-09-29T14:21:41-04:00
INGESTED 2026-10-06T11:43:08-04:00