CVE-2026-1526 | undici up to 6.23.0 WebSocket decompress data amplification
A vulnerability was found in undici. It has been declared as problematic. Impacted is the function decompress of the component WebSocket Handler. Such manipulation leads to highly compressed data.
This vulnerability is uniquely identified as CVE-2026-1526. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.