Vulnerabilities/

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

Severity:
High

Description

A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici’s ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.

Recommendation

Update the undici package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
undici
Anything's wrong? Let us know Last updated on March 13, 2026