{
  "threat_severity" : "Important",
  "public_date" : "2026-06-17T16:05:38Z",
  "bugzilla" : {
    "description" : "undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames",
    "id" : "2489980",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2489980"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-770",
  "details" : [ "Impact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\nAffected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\nAll releases starting at undici 6.17.0 are affected.\nPatches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:\nNo workaround is available. The fix must be applied through an upgrade.", "A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API." ],
  "statement" : "This Important denial of service flaw in the `undici` WebSocket client allows a remote attacker to cause unbounded memory growth. By sending numerous small or empty WebSocket frames, an unauthenticated attacker can exhaust system memory, leading to a denial of service in Red Hat products that use the affected client.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35841",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "nodejs24-1:24.18.0-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35842",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "nodejs22-1:22.23.1-2.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39246",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "nodejs22-1:22.23.1-2.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:39868",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "nodejs:24-8100020260630152626.6d880403"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41947",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "nodejs:22-8100020260703140402.6d880403"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35891",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "nodejs:24-9080020260626074955.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35892",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "nodejs:22-9080020260626075442.rhel9"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9:1782839981"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9:1782839193"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/distributed-tracing-console-plugin-rhel9:1782838753"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/logging-console-plugin-rhel9:1782841925"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1782844225"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1782839658"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/monitoring-console-plugin-rhel9:1782838476"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34342",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/troubleshooting-panel-console-plugin-rhel9:1782839494"
  }, {
    "product_name" : "Red Hat Developer Hub 1.10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36754",
    "cpe" : "cpe:/a:redhat:rhdh:1.10::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1783448184"
  }, {
    "product_name" : "Red Hat Developer Hub 1.9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41929",
    "cpe" : "cpe:/a:redhat:rhdh:1.9::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1784210921"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-10T00:00:00Z",
    "advisory" : "RHSA-2026:38009",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "nodejs26-main-26.5.0-1.3.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-11T00:00:00Z",
    "advisory" : "RHSA-2026:38236",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "nodejs24-main-24.18.0-0.3.hum1"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.16",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:36621",
    "cpe" : "cpe:/a:redhat:openshift:4.16::el9",
    "package" : "openshift4/ose-monitoring-plugin-rhel9:1783306396"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces 3.29",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36820",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3.29::el9",
    "package" : "devspaces/dashboard-rhel9:1782498792"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces 3.29",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36820",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3.29::el9",
    "package" : "devspaces/openvsx-rhel9:1783007534"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces 3.29",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36820",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3.29::el9",
    "package" : "devspaces/pluginregistry-rhel9:1782989367"
  } ],
  "package_state" : [ {
    "product_name" : "Cryostat 4",
    "fix_state" : "Not affected",
    "package_name" : "cryostat-openshift-console-plugin-npm",
    "cpe" : "cpe:/a:redhat:cryostat:4"
  }, {
    "product_name" : "Cryostat 4",
    "fix_state" : "Affected",
    "package_name" : "grafana-infinity-datasource-npm",
    "cpe" : "cpe:/a:redhat:cryostat:4"
  }, {
    "product_name" : "Cryostat 4",
    "fix_state" : "Not affected",
    "package_name" : "undici",
    "cpe" : "cpe:/a:redhat:cryostat:4"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Affected",
    "package_name" : "openshift-pipelines/pipelines-console-plugin-pf5-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Affected",
    "package_name" : "openshift-pipelines/pipelines-console-plugin-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Affected",
    "package_name" : "openshift-pipelines/pipelines-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "Red Hat AMQ Broker 7",
    "fix_state" : "Affected",
    "package_name" : "undici",
    "cpe" : "cpe:/a:redhat:amq_broker:7"
  }, {
    "product_name" : "Red Hat Build of Podman Desktop",
    "fix_state" : "Affected",
    "package_name" : "rh-podman-desktop.git",
    "cpe" : "cpe:/a:redhat:podman_desktop:1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Will not fix",
    "package_name" : "nodejs25",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Affected",
    "package_name" : "rust",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-dashboard-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-automl-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-autorag-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-eval-hub-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-gen-ai-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-maas-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-mod-arch-mlflow-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-model-registry-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift4/ose-agent-installer-ui-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift4/ose-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Affected",
    "package_name" : "odf4/ocs-client-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Affected",
    "package_name" : "odf4/odf-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Affected",
    "package_name" : "odf4/odf-multicluster-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Affected",
    "package_name" : "devspaces/code-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform/automation-portal",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform/bootc-automation-portal-rhel9",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-12151\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12151\nhttps://cna.openjsf.org/security-advisories.html\nhttps://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q" ],
  "name" : "CVE-2026-12151",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}