CVE-2026-22036

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-01-14 19:16

Updated : 2026-01-22 21:15


NVD link : CVE-2026-22036

Mitre link : CVE-2026-22036

CVE.ORG link : CVE-2026-22036


JSON object : View

Products Affected

nodejs

  • undici
CWE
CWE-770

Allocation of Resources Without Limits or Throttling