漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
undici WebSocket client vulnerable to denial of service via fragment count bypass
Vulnerability Description
Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.
Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.
All releases starting at undici 6.17.0 are affected.
Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:
No workaround is available. The fix must be applied through an upgrade.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Node.js undici 资源管理错误漏洞
Vulnerability Description
Node.js undici是Node.js基金会开源的一个HTTP/1.1客户端。 Node.js undici 6.17.0版本及以上版本存在资源管理错误漏洞,该漏洞源于对WebSocket分片数量未限制,可能导致恶意WebSocket服务器连续发送小或空的延续帧,造成客户端内存耗尽,导致拒绝服务。以下版本受到影响:6.17.0版本及以上版本。
CVSS Information
N/A
Vulnerability Type
N/A