Amazon Linux 2023 Security Advisory: ALAS2023-2026-3123
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2. (CVE-2026-19534)
undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2. (CVE-2026-85024)
Affected Packages:
nodejs22
Issue Correction:
Run dnf update nodejs22 --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3123 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
nodejs22-libs-debuginfo-22.23.2-1.amzn2023.0.3.aarch64
nodejs22-debuginfo-22.23.2-1.amzn2023.0.3.aarch64
nodejs22-full-i18n-22.23.2-1.amzn2023.0.3.aarch64
nodejs22-22.23.2-1.amzn2023.0.3.aarch64
v8-12.4-devel-12.4.254.21-1.22.23.2.1.amzn2023.0.3.aarch64
nodejs22-devel-22.23.2-1.amzn2023.0.3.aarch64
nodejs22-libs-22.23.2-1.amzn2023.0.3.aarch64
nodejs22-npm-10.9.8-1.22.23.2.1.amzn2023.0.3.aarch64
nodejs22-debugsource-22.23.2-1.amzn2023.0.3.aarch64
noarch:
nodejs22-docs-22.23.2-1.amzn2023.0.3.noarch
src:
nodejs22-22.23.2-1.amzn2023.0.3.src
x86_64:
nodejs22-libs-debuginfo-22.23.2-1.amzn2023.0.3.x86_64
nodejs22-libs-22.23.2-1.amzn2023.0.3.x86_64
nodejs22-full-i18n-22.23.2-1.amzn2023.0.3.x86_64
v8-12.4-devel-12.4.254.21-1.22.23.2.1.amzn2023.0.3.x86_64
nodejs22-22.23.2-1.amzn2023.0.3.x86_64
nodejs22-devel-22.23.2-1.amzn2023.0.3.x86_64
nodejs22-npm-10.9.8-1.22.23.2.1.amzn2023.0.3.x86_64
nodejs22-debuginfo-22.23.2-1.amzn2023.0.3.x86_64
nodejs22-debugsource-22.23.2-1.amzn2023.0.3.x86_64