OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-19534: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol

GitHub Advisories · officialPublished Sep 29, 2026Risk 37/100

### Impact The undici WebSocket client throws an uncaught `TypeError` during the opening handshake when a server's `101` response includes a `Sec-WebSocket-Protocol` header that the client never requested. The throw occurs in a `queueMicrotask` callback with no surrounding `try`/`catch`, so it propagates as an uncaught exception and terminates the Node.js process. This is a remote, unauthenticated denial of service against any application that opens a WebSocket to an attacker controlled or compromised server, or over a plaintext `ws://` connection subject to a machine-in-the-middle. It affects the default `new WebSocket(url)` usage, where no subprotocol is requested. Per RFC 6455 section 4.1, an unrequested subprotocol must fail the connection, not crash it. All releases starting at undici 6.7.0 are affected. ### Patches Upgrade to undici 6.28.1, 7.29.1, or 8.10.2. ### Workarounds No workaround is available. The fix must be applied through an upgrade.

Upgrade affected packages to a patched version: undici 6.28.1, undici 7.29.1, undici 8.10.2.

Vendor
Not specified
Product
undici
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source