CVE-2026-2229

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix update

Description

A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client's Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
56.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-18 18:22 UTC
CWE-248, CWE-1284

Weakness classes (CWE)

  • CWE-248Base

    Uncaught Exception

    An exception is thrown from a function, but it is not caught.

    cwe.mitre.org →
  • CWE-1284Base

    Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-03 13:05 UTC· ce714d77-add3-4f53-aff5-83d477b104bb
    • Reference: https://cna.openjsf.org/security-advisories.html
    • Reference: https://datatracker.ietf.org/doc/html/rfc7692
    • Reference: https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8
    • Reference: https://hackerone.com/reports/3487486
  2. CVE Modified2026-09-03 13:05 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/2xxx/CVE-2026-2229.json">CVE-2026-2229</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:13826
    • Reference: https://access.redhat.com/errata/RHSA-2026:17789
    • Reference: https://access.redhat.com/errata/RHSA-2026:21772
  3. CVE Modified2026-08-19 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:56431
    • Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+61)
  4. CVE Modified2026-08-04 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.25.0

  • go-jose_project

    go-jose3.0.0 – 3.0.5

  • go-jose_project

    go-jose4.0.0 – 4.1.4

  • golang

    go1.25.0 – 1.25.6

  • golang

    go1.24.12

  • golang

    net0.55.0

  • grpc

    grpc1.79.3

  • IBM

    App Connect EnterpriseCD 13.4.0

  • IBM

    App Connect EnterpriseLTS 12.0.26

  • IBM

    App Connect EnterpriseLTS 13.4.0

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • nodeca

    js-yaml4.0.0 – 4.2.0

  • nodeca

    js-yaml3.15.0

References & sources

Linked CVEs

Show 17 more CVEs
IDCVE-2026-2229