CVE-2026-1528

Red Hat Security Advisory: Cluster Observability Operator 1.5.0

Description

A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici's ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
40.5 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-01 14:36 UTC
CWE-248, CWE-1284

Weakness classes (CWE)

  • CWE-248Base

    Uncaught Exception

    An exception is thrown from a function, but it is not caught.

    cwe.mitre.org →
  • CWE-1284Base

    Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-03 13:04 UTC· ce714d77-add3-4f53-aff5-83d477b104bb
    • Reference: https://cna.openjsf.org/security-advisories.html
    • Reference: https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj
    • Reference: https://hackerone.com/reports/3537648
    • Reference: https://cna.openjsf.org/security-advisories.html
  2. CVE Modified2026-09-03 13:04 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/1xxx/CVE-2026-1528.json">CVE-2026-1528</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:13826
    • Reference: https://access.redhat.com/errata/RHSA-2026:17789
    • Reference: https://access.redhat.com/errata/RHSA-2026:21772
  3. CVE Modified2026-08-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)
  4. CVE Modified2026-08-04 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • digitalbazaar

    forge1.3.3

  • digitalbazaar

    forge1.4.0

  • go

    golang.org/x/net

  • go

    golang.org/x/oauth2

  • go

    stdlib1.24.0-0

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    http20.53.0

  • golang

    net0.55.0

  • handlebarsjs

    handlebars4.0.0 – 4.7.9

  • immutable-js

    immutable3.0.0 – 3.8.3

  • immutable-js

    immutable4.0.0 – 4.3.7

  • immutable-js

    immutable5.0.0 – 5.1.5

References & sources

Linked CVEs

Show 16 more CVEs
IDCVE-2026-1528