FlawAtlas
Search the atlas
CVE-2026-22036 Moderate

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

Exploit probability 0.4%
Published January 14, 2026
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

210 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:10074-1
related OPENSUSE-SU-2026:10075-1
related OPENSUSE-SU-2026:20236-1
related SUSE-SU-2026:0295-1
related SUSE-SU-2026:0301-1
related SUSE-SU-2026:0435-1
related SUSE-SU-2026:0457-1
related SUSE-SU-2026:20436-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-22036

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

View original source

05 / REFERENCES

Further evidence