CVE-2026-1528
Red Hat Security Advisory: Cluster Observability Operator 1.5.0
Description
A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici's ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.
Metrics
Weakness classes (CWE)
CWE-248Base
Uncaught Exception
An exception is thrown from a function, but it is not caught.
cwe.mitre.org →CWE-1284Base
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-03 13:04 UTC· ce714d77-add3-4f53-aff5-83d477b104bb
- Reference: https://cna.openjsf.org/security-advisories.html
- Reference: https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj
- Reference: https://hackerone.com/reports/3537648
- Reference: https://cna.openjsf.org/security-advisories.html
- CVE Modified2026-09-03 13:04 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/1xxx/CVE-2026-1528.json">CVE-2026-1528</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:13826
- Reference: https://access.redhat.com/errata/RHSA-2026:17789
- Reference: https://access.redhat.com/errata/RHSA-2026:21772
- CVE Modified2026-08-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42) → Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)
- CVE Modified2026-08-04 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42) → Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
digitalbazaar
forge1.3.3
digitalbazaar
forge1.4.0
go
golang.org/x/net
go
golang.org/x/oauth2
go
stdlib1.24.0-0
golang
go1.26.0 – 1.26.3
golang
go1.25.10
golang
http20.53.0
golang
net0.55.0
handlebarsjs
handlebars4.0.0 – 4.7.9
immutable-js
immutable3.0.0 – 3.8.3
immutable-js
immutable4.0.0 – 4.3.7
immutable-js
immutable5.0.0 – 5.1.5
References & sources
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-cfm4-qjh2-4765web
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwpweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-33894advisory
- https://datatracker.ietf.org/doc/html/rfc2313#section-8web
- https://github.com/digitalbazaar/forgepackage
- https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QEweb
- https://www.rfc-editor.org/rfc/rfc8017.htmlweb
- https://access.redhat.com/security/cve/CVE-2026-33894vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2452464issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33894.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:24761vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34342vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:9742vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:13826vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22629vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:21017vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24853vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19375vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22465vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22840vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9277
A flaw was found in the shell-quote component.
criticalCVSSv3 8.1 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-6321
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-48779
A flaw was found in ws, an open source WebSocket client and server.
highCVSSv3 7.5 - CVE-2026-4867
A flaw was found in path-to-regexp.
highCVSSv3 7.5 - CVE-2026-4800
A flaw was found in lodash.
criticalCVSSv3 9.8 - CVE-2026-42506
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-33941
A flaw was found in Handlebars.
highCVSSv3 8.3 - CVE-2026-33940
A flaw was found in Handlebars.js.
highCVSSv3 8.1 - CVE-2026-33939
A flaw was found in Handlebars.js.
highCVSSv3 7.5 - CVE-2026-33938
A flaw was found in Handlebars.
highCVSSv3 8.1 - CVE-2026-33937
A flaw was found in Handlebars.
criticalCVSSv3 9.8 - CVE-2026-33896
A flaw was found in Forge (also known as node-forge), a JavaScript implementation of Transport Layer Security (TLS).
criticalCVSSv3 9.1 - CVE-2026-33895
A flaw was found in Forge (also called `node-forge`), a JavaScript library used for Transport Layer Security (TLS).
highCVSSv3 7.5 - CVE-2026-33894
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript.
highCVSSv3 7.5 - CVE-2026-33891
A flaw was found in the node-forge library, a JavaScript implementation of Transport Layer Security.
highCVSSv3 7.5 - CVE-2026-33814
A flaw was found in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2).
highCVSSv3 7.5 - CVE-2026-33671
A flaw was found in Picomatch, a JavaScript glob matcher.
highCVSSv3 7.5 - CVE-2026-33228
A flaw was found in flatted, a JavaScript Object Notation (JSON) parser designed for handling circular data structures.
criticalCVSSv3 9.8 - CVE-2026-32141
A denial of service flaw has been discovered in the flatted npm library.
highCVSSv3 7.5 - CVE-2026-29063
A flaw was found in Immutable.js, a library for persistent immutable data structures.
criticalCVSSv3 9.8
Show 16 more CVEs
- CVE-2026-25681
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-25680
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.5 - CVE-2026-2229
A flaw was found in the undici WebSocket client.
highCVSSv3 7.5 - CVE-2026-1526
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12143
A flaw was found in form-data, a library for creating readable multipart/form-data streams.
highCVSSv3 7.5 - CVE-2025-58190
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of…
— - CVE-2025-47911
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denia…
— - CVE-2025-22872
A flaw was found in the HTML tokenizer component.
— - CVE-2025-22870
A flaw was found in proxy host matching.
— - CVE-2025-22868
A flaw was found in the `golang.org/x/oauth2/jws` package in the token parsing component.
— - CVE-2024-52011
A flaw was found in launch-editor, a tool that allows users to open files with line numbers in an editor from Node.js.
highCVSSv3 8.3 - CVE-2024-45338
A flaw was found in golang.org/x/net/html.
— - CVE-2024-4068
A flaw was found in the NPM package `braces.` It fails to limit the number of characters it can handle, which could lead to memory exhaus…
highCVSSv3 7.5 - CVE-2021-33623
A flaw was found in nodejs-trim-newlines.
— - CVE-2020-7753
A flaw was found in the npm library trim where a specifically crafted input can cause a regular expression to take an abnormal amount of…
highCVSSv3 7.5