Disclosure summary
## Impact undici's `WebSocketStream` crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls `abort()` on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with a `TypeError`, and the handler discards that promise. The unobserved rejection surfaces as an `unhandledRejection` and, under Node.js's default behavior, terminates the process. A malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the `WebSocketStream` API and writing through a writer, which is the standard way to write. All releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0. ## Patches Upgrade to undici v7.29.1 or v8.10.2. ## Workarounds No workaround is available.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-rx4f-c7p8-82vq
Open original source · Updated Sep 29, 2026
undici vulnerable to Denial of Service via WebSocketStream unclean close
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | undici | >= 7.0.0, < 7.29.1 | 7.29.1 |
| npm | undici | >= 8.0.0, < 8.10.2 | 8.10.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T14:10:32-04:00
MODIFIED 2026-09-29T14:10:33-04:00
INGESTED 2026-10-06T11:43:08-04:00