CVE-2026-85014 PUBLISHED

undici vulnerable to Denial of Service via WebSocketStream unclean close

Assigner: openjs
Reserved: 02.09.2026 Published: 04.09.2026 Updated: 04.09.2026

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 5.9

Product Status

Vendor undici
Product undici
Versions Default: unaffected
  • affected from 7.0.0 to 7.29.1 (excl.)
  • Version 7.29.1 is unaffected
  • affected from 8.0.0 to 8.10.2 (excl.)
  • Version 8.10.2 is unaffected

Credits

  • Yanhaoxi reporter
  • mcollina remediation developer
  • UlisesGascon remediation reviewer

References

Problem Types

  • CWE-248: Uncaught Exception CWE
  • CWE-754: Improper Check for Unusual or Exceptional Conditions CWE