CVE-2026-2229
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix update
Description
A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client's Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.
Metrics
Weakness classes (CWE)
CWE-248Base
Uncaught Exception
An exception is thrown from a function, but it is not caught.
cwe.mitre.org →CWE-1284Base
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-03 13:05 UTC· ce714d77-add3-4f53-aff5-83d477b104bb
- Reference: https://cna.openjsf.org/security-advisories.html
- Reference: https://datatracker.ietf.org/doc/html/rfc7692
- Reference: https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8
- Reference: https://hackerone.com/reports/3487486
- CVE Modified2026-09-03 13:05 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/2xxx/CVE-2026-2229.json">CVE-2026-2229</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:13826
- Reference: https://access.redhat.com/errata/RHSA-2026:17789
- Reference: https://access.redhat.com/errata/RHSA-2026:21772
- CVE Modified2026-08-19 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:56431
- Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42) → Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+61)
- CVE Modified2026-08-04 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42) → Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10 (+42)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
bitnami
golang1.25.0
go-jose_project
go-jose3.0.0 – 3.0.5
go-jose_project
go-jose4.0.0 – 4.1.4
golang
go1.25.0 – 1.25.6
golang
go1.24.12
golang
net0.55.0
grpc
grpc1.79.3
IBM
App Connect EnterpriseCD 13.4.0
IBM
App Connect EnterpriseLTS 12.0.26
IBM
App Connect EnterpriseLTS 13.4.0
IBM
Concert< 3.0.0
fixed in 3.0.0
nodeca
js-yaml4.0.0 – 4.2.0
nodeca
js-yaml3.15.0
References & sources
- https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvqweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-1527advisory
- https://hackerone.com/reports/3487198web
- https://cna.openjsf.org/security-advisories.htmlweb
- https://github.com/nodejs/undicipackage
- https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6web
- https://nvd.nist.gov/vuln/detail/CVE-2026-13676advisory
- https://github.com/fastify/fast-uri/pull/188web
- https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05web
- https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bdweb
- https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1dweb
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.jsonweb
- https://github.com/fastify/fast-uri/releases/tag/v4.0.1web
- https://github.com/fastify/fast-uri/releases/tag/v3.1.3web
- https://github.com/fastify/fast-uri/releases/tag/v2.4.2web
- https://github.com/fastify/fast-uripackage
- https://bugzilla.redhat.com/show_bug.cgi?id=2494197web
- https://access.redhat.com/security/cve/CVE-2026-13676web
- https://access.redhat.com/errata/RHSA-2026:48126web
- https://access.redhat.com/errata/RHSA-2026:48124web
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9679
A flaw was found in undici.
mediumCVSSv3 5.9 - CVE-2026-9358
A flaw was found in postcss.
mediumCVSSv3 4.3 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-6733
A flaw was found in undici.
lowCVSSv3 3.7 - CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-6321
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-59869
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-53550
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
mediumCVSSv3 5.3 - CVE-2026-48801
A flaw was found in linkify-it, a library for recognizing links with full Unicode support.
highCVSSv3 7.5 - CVE-2026-48779
A flaw was found in ws, an open source WebSocket client and server.
highCVSSv3 7.5 - CVE-2026-45736
A flaw was found in ws, an open source WebSocket client and server for Node.js.
highCVSSv3 7.5 - CVE-2026-45409
A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications.
mediumCVSSv3 5.3 - CVE-2026-42342
A flaw was found in React Router and @remix-run/server-runtime.
highCVSSv3 7.5 - CVE-2026-41907
A flaw was found in uuid.
high - CVE-2026-41650
A flaw was found in fast-xml-parser.
mediumCVSSv3 6.1 - CVE-2026-41305
A flaw was found in PostCSS.
mediumCVSSv3 6.1 - CVE-2026-40181
A flaw was found in React Router.
mediumCVSSv3 6.1 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-35469
A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver.
highCVSSv3 6.5 - CVE-2026-34986
A flaw was found in Go JOSE, a library for handling JSON Web Encryption (JWE) objects.
highCVSSv3 7.5 - CVE-2026-34043
A flaw was found in serialize-javascript.
mediumCVSSv3 5.9 - CVE-2026-33750
A flaw was found in the brace-expansion library, a component used for generating strings based on patterns.
mediumCVSSv3 6.5 - CVE-2026-33672
A flaw was found in picomatch, a JavaScript glob matcher.
mediumCVSSv3 5.3
Show 17 more CVEs
- CVE-2026-33671
A flaw was found in Picomatch, a JavaScript glob matcher.
highCVSSv3 7.5 - CVE-2026-33349
A flaw was found in fast-xml-parser.
mediumCVSSv3 5.9 - CVE-2026-33186
A flaw was found in gRPC-Go, the Go language implementation of gRPC.
criticalCVSSv3 9.1 - CVE-2026-25645
A flaw was found in the `requests` HTTP library, specifically in the `requests.utils.extract_zipped_paths()` function, which is used to l…
mediumCVSSv3 4.4 - CVE-2026-22036
A flaw was found in Undici, an HTTP/1.1 client for Node.js.
mediumCVSSv3 5.9 - CVE-2026-1527
A flaw was found in undici, a Node.js HTTP/1.1 client.
mediumCVSSv3 4.6 - CVE-2026-1526
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-1525
A flaw was found in undici, a Node.js HTTP/1.1 client.
mediumCVSSv3 6.5 - CVE-2026-13676
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-13149
A flaw was found in brace-expansion.
high - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12143
A flaw was found in form-data, a library for creating readable multipart/form-data streams.
highCVSSv3 7.5 - CVE-2026-11525
A flaw was found in undici.
lowCVSSv3 3.7 - CVE-2025-68470
An open redirect flaw has been discovered in the react-router npm library.
mediumCVSSv3 6.5 - CVE-2025-64718
A prototype pollution flaw has been discovered in the js-yaml npm library.
mediumCVSSv3 5.3 - CVE-2025-61729
A flaw was found in golang.
highCVSSv3 7.5 - CVE-2025-61726
The net/url package does not set a limit on the number of query parameters in a query.
highCVSSv3 7.5