Allocation of Resources Without Limits or Throttling Affecting undici package, versions >=8.0.0 <8.5.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.43% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-UNDICI-17372611
  • published18 Jun 2026
  • disclosed17 Jun 2026
  • creditStrickland

Introduced: 17 Jun 2026

CVE-2026-9675  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade undici to version 8.5.0 or higher.

Overview

undici is an An HTTP/1.1 client, written from scratch for Node.js

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the handling of fragmented WebSocket messages. An attacker can cause unbounded memory growth and exhaust system resources by sending numerous small fragments that individually pass validation but collectively exceed the intended payload size limit.

CVSS Base Scores

version 4.0
version 3.1