-
-
Notifications
You must be signed in to change notification settings - Fork 4k
Open
Description
While working in chatbox project, I found that the application uses undici, which is affected by a denial-of-service vulnerability (CVE-2026-1526). The issue occurs in the WebSocket client’s PerMessageDeflate.decompress() method, which decompresses incoming frames without limiting the size of the decompressed data.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels