CWE-248
AllowedUncaught Exception
Abstraction: Base · Status: Draft
An exception is thrown from a function, but it is not caught.
610 vulnerabilities reference this CWE, most recent first.
GHSA-3G9H-9HP4-654V
Vulnerability from github – Published: 2026-03-18 20:11 – Updated: 2026-03-25 18:12Summary
The SiYuan kernel WebSocket server accepts unauthenticated connections when a specific “auth keepalive” query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON.
A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service.
Details
1. Authentication Bypass via Keepalive Query
Unauthenticated connections are accepted if the request URI matches a specific pattern intended for an authentication page keepalive.
File: kernel/server/serve.go
if !authOk {
authOk = strings.Contains(s.Request.RequestURI, "/ws?app=siyuan") &&
strings.Contains(s.Request.RequestURI, "&id=auth&type=auth")
}
2. Unsafe Type Assertions on Untrusted Input
Incoming JSON messages are parsed into a generic map and fields are accessed without validation.
File: kernel/server/serve.go
cmdStr := request["cmd"].(string)
cmdId := request["reqId"].(float64)
param := request["param"].(map[string]interface{})
Malformed or missing fields trigger a runtime panic. The handler does not implement local panic recovery, allowing crashes to propagate.
PoC
Step 1 — Prepare workspace directory
mkdir -p ./workspace
Step 2 — Run SiYuan container
docker run -d \
-p 6806:6806 \
-e SIYUAN_ACCESS_AUTH_CODE_BYPASS=true \
-v $(pwd)/workspace:/siyuan/workspace \
b3log/siyuan \
--workspace=/siyuan/workspace
Service becomes reachable at http://127.0.0.1:6806
Step 3 — Confirm service availability
Open in browser:
http://127.0.0.1:6806
Step 4 — Connect to unauthenticated WebSocket endpoint
ws://127.0.0.1:6806/ws?app=siyuan&id=auth&type=auth
This connection is accepted without credentials.
Step 5 — Send malformed payload
Payload:
{}
Step 6 — Observe behavior
Monitor container logs:
docker logs -f <container_id>
Impact
An unauthenticated attacker with network access can repeatedly crash the kernel, causing persistent denial of service.
Impact is highest when the service is exposed beyond localhost (e.g., Docker deployments, reverse proxies, LAN access, or public hosting).
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 3.6.1"
},
"package": {
"ecosystem": "Go",
"name": "github.com/siyuan-note/siyuan/kernel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.6.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-33203"
],
"database_specific": {
"cwe_ids": [
"CWE-248",
"CWE-306"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-18T20:11:00Z",
"nvd_published_at": "2026-03-20T23:16:45Z",
"severity": "HIGH"
},
"details": "## Summary\nThe SiYuan kernel WebSocket server accepts unauthenticated connections when a specific \u201cauth keepalive\u201d query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON.\n\nA remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service.\n\n## Details\n**1. Authentication Bypass via Keepalive Query**\n\nUnauthenticated connections are accepted if the request URI matches a specific pattern intended for an authentication page keepalive.\n\n**File: kernel/server/serve.go**\n\n```\nif !authOk {\n authOk = strings.Contains(s.Request.RequestURI, \"/ws?app=siyuan\") \u0026\u0026\n strings.Contains(s.Request.RequestURI, \"\u0026id=auth\u0026type=auth\")\n}\n\n```\n\n**2. Unsafe Type Assertions on Untrusted Input**\n\nIncoming JSON messages are parsed into a generic map and fields are accessed without validation.\n\n**File: kernel/server/serve.go**\n\n```\ncmdStr := request[\"cmd\"].(string)\ncmdId := request[\"reqId\"].(float64)\nparam := request[\"param\"].(map[string]interface{})\n\n```\nMalformed or missing fields trigger a runtime panic.\nThe handler does not implement local panic recovery, allowing crashes to propagate.\n\n## PoC\n**Step 1 \u2014 Prepare workspace directory**\n\n```sh\nmkdir -p ./workspace\n```\n\n**Step 2 \u2014 Run SiYuan container**\n\n```\ndocker run -d \\\n -p 6806:6806 \\\n -e SIYUAN_ACCESS_AUTH_CODE_BYPASS=true \\\n -v $(pwd)/workspace:/siyuan/workspace \\\n b3log/siyuan \\\n --workspace=/siyuan/workspace\n```\n\nService becomes reachable at http://127.0.0.1:6806\n\n**Step 3 \u2014 Confirm service availability**\n\nOpen in browser:\n\n```sh\nhttp://127.0.0.1:6806\n```\n\n**Step 4 \u2014 Connect to unauthenticated WebSocket endpoint**\n\n```sh\nws://127.0.0.1:6806/ws?app=siyuan\u0026id=auth\u0026type=auth\n```\n\nThis connection is accepted without credentials.\n\n**Step 5 \u2014 Send malformed payload**\n\nPayload:\n\n```sh\n\n{}\n\n```\n\n**Step 6 \u2014 Observe behavior**\n\nMonitor container logs:\n\n```sh\n\ndocker logs -f \u003ccontainer_id\u003e\n\n```\n## Impact\nAn unauthenticated attacker with network access can repeatedly crash the kernel, causing persistent denial of service.\n\nImpact is highest when the service is exposed beyond localhost (e.g., Docker deployments, reverse proxies, LAN access, or public hosting).",
"id": "GHSA-3g9h-9hp4-654v",
"modified": "2026-03-25T18:12:26Z",
"published": "2026-03-18T20:11:00Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-3g9h-9hp4-654v"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33203"
},
{
"type": "PACKAGE",
"url": "https://github.com/siyuan-note/siyuan"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass"
}
GHSA-3GMG-R977-HQCC
Vulnerability from github – Published: 2025-01-23 12:32 – Updated: 2026-02-23 12:31Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 allows a highly privileged attacker to cause denial of service via configuration change.
{
"affected": [],
"aliases": [
"CVE-2025-0648"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-23T11:15:11Z",
"severity": "MODERATE"
},
"details": "Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 allows a highly privileged attacker to cause denial of service via configuration change.",
"id": "GHSA-3gmg-r977-hqcc",
"modified": "2026-02-23T12:31:29Z",
"published": "2025-01-23T12:32:36Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0648"
},
{
"type": "WEB",
"url": "https://empower.m-files.com/security-advisories/CVE-2025-0648"
},
{
"type": "WEB",
"url": "https://product.m-files.com/security-advisories/cve-2025-0648"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-3H9V-XWGF-H5C5
Vulnerability from github – Published: 2026-07-18 15:31 – Updated: 2026-07-18 15:31SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service.
{
"affected": [],
"aliases": [
"CVE-2024-58357"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-18T14:17:08Z",
"severity": "HIGH"
},
"details": "SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service.",
"id": "GHSA-3h9v-xwgf-h5c5",
"modified": "2026-07-18T15:31:48Z",
"published": "2026-07-18T15:31:48Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h4f5-h82v-5w4r"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58357"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-rand-time"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-3HJG-VC7R-RCRW
Vulnerability from github – Published: 2022-04-07 15:20 – Updated: 2022-04-07 15:20Impact
An attacker using the Trailer header as part of the request against proxy endpoints has the ability to take down the server.
All Podium layouts that include podlets with proxy endpoints are affected.
Patches
@podium/layout which is the main way developers/users are vulnerable to this exploit, has been patched in version 4.6.110. All earlier versions are vulnerable.
@podium/proxy which is the source of the vulnerability and is used by @podium/layout has been patched in version 4.2.74. All earlier versions are vulnerable.
Workarounds
It is not easily possible to work around this issue without upgrading. We recommend upgrading @podium/layout and/or @podium/proxy as soon as possible.
For more information
If you have any questions or comments about this advisory: * Open an issue in podium-lib/issues
Credits
The vulnerability was reported by krynos from Ercoli Consulting via FINN.no's private bug bounty program
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@podium/layout"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6.110"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "@podium/proxy"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.2.74"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-24822"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": true,
"github_reviewed_at": "2022-04-07T15:20:23Z",
"nvd_published_at": "2022-04-06T18:15:00Z",
"severity": "HIGH"
},
"details": "### Impact\nAn attacker using the `Trailer` header as part of the request against proxy endpoints has the ability to take down the server.\nAll Podium layouts that include podlets with proxy endpoints are affected.\n\n### Patches\n`@podium/layout` which is the main way developers/users are vulnerable to this exploit, has been patched in version `4.6.110`. All earlier versions are vulnerable.\n`@podium/proxy` which is the source of the vulnerability and is used by `@podium/layout` has been patched in version `4.2.74`. All earlier versions are vulnerable.\n\n### Workarounds\nIt is not easily possible to work around this issue without upgrading. We recommend upgrading `@podium/layout` and/or `@podium/proxy` as soon as possible.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [podium-lib/issues](https://github.com/podium-lib/issues)\n\n### Credits\nThe vulnerability was reported by [krynos](https://hackerone.com/krynos) from [Ercoli Consulting](https://www.ercoliconsulting.eu/) via FINN.no\u0027s private bug bounty program\n",
"id": "GHSA-3hjg-vc7r-rcrw",
"modified": "2022-04-07T15:20:23Z",
"published": "2022-04-07T15:20:23Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/podium-lib/proxy/security/advisories/GHSA-3hjg-vc7r-rcrw"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24822"
},
{
"type": "WEB",
"url": "https://github.com/podium-lib/layout/commit/fe43e655432b0a5f07b6475f67babcc2588fb039"
},
{
"type": "WEB",
"url": "https://github.com/podium-lib/proxy/commit/9698a40df081217ce142d4de71f929baaa339cdf"
},
{
"type": "WEB",
"url": "https://github.com/podium-lib/layout/releases/tag/v4.6.110"
},
{
"type": "WEB",
"url": "https://github.com/podium-lib/proxy/releases/tag/v4.2.74"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Denial of Service vulnerability in @podium/layout and @podium/proxy"
}
GHSA-3MFM-PFV2-VMRP
Vulnerability from github – Published: 2022-10-01 00:00 – Updated: 2022-10-06 00:00A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation during processing of CIP packets. An attacker could exploit this vulnerability by sending a malformed CIP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
{
"affected": [],
"aliases": [
"CVE-2022-20919"
],
"database_specific": {
"cwe_ids": [
"CWE-20",
"CWE-248",
"CWE-755"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-30T19:15:00Z",
"severity": "HIGH"
},
"details": "A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation during processing of CIP packets. An attacker could exploit this vulnerability by sending a malformed CIP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.",
"id": "GHSA-3mfm-pfv2-vmrp",
"modified": "2022-10-06T00:00:55Z",
"published": "2022-10-01T00:00:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20919"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-cip-dos-9rTbKLt9"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-3Q6M-V84F-6P9H
Vulnerability from github – Published: 2023-10-30 15:08 – Updated: 2023-11-01 06:07quic-go is an implementation of the QUIC transport protocol in Go. By serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic) when the node attempted to drop the Handshake packet number space.
Impact
An attacker can bring down a quic-go node with very minimal effort. Completing the QUIC handshake only requires sending and receiving a few packets.
Patches
v0.37.3 contains a patch. Versions before v0.37.0 are not affected.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/quic-go/quic-go"
},
"ranges": [
{
"events": [
{
"introduced": "0.37.0"
},
{
"fixed": "0.37.3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2023-46239"
],
"database_specific": {
"cwe_ids": [
"CWE-248",
"CWE-476"
],
"github_reviewed": true,
"github_reviewed_at": "2023-10-30T15:08:05Z",
"nvd_published_at": "2023-10-31T16:15:09Z",
"severity": "HIGH"
},
"details": "quic-go is an implementation of the [QUIC](https://datatracker.ietf.org/doc/html/rfc9000) transport protocol in Go. By serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic) when the node attempted to drop the Handshake packet number space.\n\n**Impact**\n\nAn attacker can bring down a quic-go node with very minimal effort. Completing the QUIC handshake only requires sending and receiving a few packets.\n\n**Patches**\n\n[v0.37.3](https://github.com/quic-go/quic-go/releases/tag/v0.37.3) contains a patch. Versions before v0.37.0 are not affected.",
"id": "GHSA-3q6m-v84f-6p9h",
"modified": "2023-11-01T06:07:08Z",
"published": "2023-10-30T15:08:05Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/quic-go/quic-go/security/advisories/GHSA-3q6m-v84f-6p9h"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46239"
},
{
"type": "WEB",
"url": "https://github.com/quic-go/quic-go/commit/b6a4725b60f1fe04e8f1ddcc3114e290fcea1617"
},
{
"type": "PACKAGE",
"url": "https://github.com/quic-go/quic-go"
},
{
"type": "WEB",
"url": "https://github.com/quic-go/quic-go/releases/tag/v0.37.3"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "quic-go vulnerable to pointer dereference that can lead to panic"
}
GHSA-3QHF-M339-9G5V
Vulnerability from github – Published: 2025-07-04 22:06 – Updated: 2026-07-16 18:30A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.
Thank you to Rich Harang for reporting this issue.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "mcp"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2025-53366"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": true,
"github_reviewed_at": "2025-07-04T22:06:49Z",
"nvd_published_at": "2025-07-04T22:15:22Z",
"severity": "HIGH"
},
"details": "A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures.\n\nThank you to Rich Harang for reporting this issue.",
"id": "GHSA-3qhf-m339-9g5v",
"modified": "2026-07-16T18:30:56Z",
"published": "2025-07-04T22:06:49Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-3qhf-m339-9g5v"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53366"
},
{
"type": "WEB",
"url": "https://github.com/modelcontextprotocol/python-sdk/pull/822"
},
{
"type": "WEB",
"url": "https://github.com/modelcontextprotocol/python-sdk/commit/29c69e6a47d0104d0afcea6ac35e7ab02fde809a"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-3qhf-m339-9g5v"
},
{
"type": "PACKAGE",
"url": "https://github.com/modelcontextprotocol/python-sdk"
},
{
"type": "WEB",
"url": "https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.9.4"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/mcp/PYSEC-2026-1616.yaml"
},
{
"type": "WEB",
"url": "https://pypi.org/project/mcp"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS"
}
GHSA-3WWX-PV8P-Q78V
Vulnerability from github – Published: 2026-09-28 21:42 – Updated: 2026-09-28 21:42Impact
undici's WebSocket client (including Node.js's bundled globalThis.WebSocket) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. In lib/web/websocket/permessage-deflate.js, the size-limit cleanup calls removeAllListeners() on the internal zlib InflateRaw, removing its error listener, but leaves the stream running. The inflater then emits a Z_DATA_ERROR with no listener attached, which Node.js treats as a fatal unhandled error event and terminates the process. Application error/close handlers on the public WebSocket cannot observe or prevent this, because the failing object is the internal InflateRaw.
A malicious or compromised WebSocket server can crash a client with a single connection, unauthenticated and without any application mistake. The attack is asymmetric (about 130 KB on the wire expands past the limit) and can be repeated on reconnect (crash loop).
Affected applications are those using the undici WebSocket client (new WebSocket(...)) or Node.js's bundled globalThis.WebSocket that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.
Patches
Upgrade to undici v6.28.1, v7.29.1 or v8.10.2.
Workarounds
No workaround is available.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "undici"
},
"ranges": [
{
"events": [
{
"introduced": "6.25.0"
},
{
"fixed": "6.28.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "undici"
},
"ranges": [
{
"events": [
{
"introduced": "7.28.0"
},
{
"fixed": "7.29.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "undici"
},
"ranges": [
{
"events": [
{
"introduced": "8.1.0"
},
{
"fixed": "8.10.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-85024"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-28T21:42:37Z",
"nvd_published_at": "2026-09-04T17:17:02Z",
"severity": "MODERATE"
},
"details": "## Impact\n\nundici\u0027s WebSocket client (including Node.js\u0027s bundled `globalThis.WebSocket`) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. In `lib/web/websocket/permessage-deflate.js`, the size-limit cleanup calls `removeAllListeners()` on the internal zlib `InflateRaw`, removing its `error` listener, but leaves the stream running. The inflater then emits a `Z_DATA_ERROR` with no listener attached, which Node.js treats as a fatal unhandled `error` event and terminates the process. Application `error`/`close` handlers on the public WebSocket cannot observe or prevent this, because the failing object is the internal `InflateRaw`.\n\nA malicious or compromised WebSocket server can crash a client with a single connection, unauthenticated and without any application mistake. The attack is asymmetric (about 130 KB on the wire expands past the limit) and can be repeated on reconnect (crash loop).\n\nAffected applications are those using the undici WebSocket client (`new WebSocket(...)`) or Node.js\u0027s bundled `globalThis.WebSocket` that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\n## Patches\n\nUpgrade to undici v6.28.1, v7.29.1 or v8.10.2.\n\n## Workarounds\n\nNo workaround is available.",
"id": "GHSA-3wwx-pv8p-q78v",
"modified": "2026-09-28T21:42:37Z",
"published": "2026-09-28T21:42:37Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85024"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f"
},
{
"type": "WEB",
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"type": "PACKAGE",
"url": "https://github.com/nodejs/undici"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/releases/tag/v6.28.1"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/releases/tag/v7.29.1"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/releases/tag/v8.10.2"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression"
}
GHSA-3X6R-WXXG-53VV
Vulnerability from github – Published: 2026-08-05 20:26 – Updated: 2026-08-05 20:261. Summary
A transport failure during the initial Infinite Scale TUS creation POST can return (nil response, non-nil error). Rclone dereferences the nil response before processing the error and panics. The production CreateUploader path reproduced the crash against a closed endpoint.
The security case is deployment-dependent. A one-shot upload already fails when its endpoint resets, while RC jobs recover panics in fs/rc/jobs/job.go and return a job error. The incremental denial of service is strongest in a long-lived VFS mount or concurrent/multi-remote CLI process where the upload runs in an unrecovered goroutine and the panic terminates unrelated work.
2. Affected Assets & Attack Surface
- Verified rclone revision:
a0c09f1381ae93e2a9a33c529d170186c61ad058(v1.74.0-240-ga0c09f138) - Current-master check:
backend/webdav/tus.gowas unchanged at master commit961266888fe797390c535386f3b3aa46f4853602on 2026-07-18 - Response evaluation:
backend/webdav/tus.go:45-59 - Creation path:
backend/webdav/tus.go:61-107 - Unrecovered VFS caller:
vfs/write.go:71-81 - Contained RC caller:
fs/rc/jobs/job.go:107-115 - Configuration: Infinite Scale WebDAV uploads using TUS
- Code triggers: any pre-response transport failure, including refusal, reset, timeout, DNS/TLS/proxy failure, or cancellation
- Security trigger: a malicious/compromised configured endpoint resets an upload in a long-lived or multi-workload process
3. Technical Root Cause Analysis
getTusLocationOrRetry switches on resp.StatusCode before checking whether resp is nil or handling the accompanying error. A nil response is valid when the HTTP transaction fails before a response is parsed. There is no recovery boundary in the WebDAV operation itself. Whether the panic is process-fatal depends on its caller: the VFS write path starts operations.Rcat in an unrecovered goroutine (vfs/write.go:71-81), whereas RC jobs wrap their function in recover (fs/rc/jobs/job.go:107-115).
4. Proof-of-Concept & Evidence
- Configure the actual Infinite Scale creation path to a closed local endpoint.
- Invoke
Object.CreateUploader. - The POST returns a transport error and no response.
getTusLocationOrRetrydereferencesresp.StatusCodeand panics.
A remote endpoint can produce the same (nil response, non-nil error) state by accepting and resetting the connection before returning an HTTP response. TLS prevents arbitrary response modification but does not prevent the configured endpoint from closing or resetting its own connection. Refusal, DNS, TLS, proxy, and cancellation failures exercise the code defect but do not by themselves identify a remote security actor.
5. Impact Assessment
In an unrecovered CLI or VFS upload goroutine, the panic terminates the rclone process and any unrelated work it hosts. A hostile configured endpoint can repeat the condition whenever the victim initiates a TUS upload. RC jobs are excluded from the process-wide impact because their execution boundary recovers the panic and records an error. In a one-shot process dedicated to the hostile endpoint, the incremental security impact over an ordinary transport error is limited.
6. Remediation Guidance
- Check
resp == nilbefore accessing response fields. - Pass transport errors through the existing retry policy and return a normal error after exhaustion.
- Test refusal, reset, timeout, DNS, TLS, proxy, and cancellation paths.
- Add panic containment to long-lived worker goroutines as defense in depth; keep nil handling as the primary fix.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 1.74.0"
},
"package": {
"ecosystem": "Go",
"name": "github.com/rclone/rclone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.75.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-248",
"CWE-476"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-05T20:26:07Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "## 1. Summary\n\nA transport failure during the initial Infinite Scale TUS creation POST can return `(nil response, non-nil error)`. Rclone dereferences the nil response before processing the error and panics. The production `CreateUploader` path reproduced the crash against a closed endpoint.\n\nThe security case is deployment-dependent. A one-shot upload already fails when its endpoint resets, while RC jobs recover panics in `fs/rc/jobs/job.go` and return a job error. The incremental denial of service is strongest in a long-lived VFS mount or concurrent/multi-remote CLI process where the upload runs in an unrecovered goroutine and the panic terminates unrelated work.\n\n## 2. Affected Assets \u0026 Attack Surface\n\n- Verified rclone revision: `a0c09f1381ae93e2a9a33c529d170186c61ad058` (`v1.74.0-240-ga0c09f138`)\n- Current-master check: `backend/webdav/tus.go` was unchanged at master commit `961266888fe797390c535386f3b3aa46f4853602` on 2026-07-18\n- Response evaluation: `backend/webdav/tus.go:45-59`\n- Creation path: `backend/webdav/tus.go:61-107`\n- Unrecovered VFS caller: `vfs/write.go:71-81`\n- Contained RC caller: `fs/rc/jobs/job.go:107-115`\n- Configuration: Infinite Scale WebDAV uploads using TUS\n- Code triggers: any pre-response transport failure, including refusal, reset, timeout, DNS/TLS/proxy failure, or cancellation\n- Security trigger: a malicious/compromised configured endpoint resets an upload in a long-lived or multi-workload process\n\n## 3. Technical Root Cause Analysis\n\n`getTusLocationOrRetry` switches on `resp.StatusCode` before checking whether `resp` is nil or handling the accompanying error. A nil response is valid when the HTTP transaction fails before a response is parsed. There is no recovery boundary in the WebDAV operation itself. Whether the panic is process-fatal depends on its caller: the VFS write path starts `operations.Rcat` in an unrecovered goroutine (`vfs/write.go:71-81`), whereas RC jobs wrap their function in `recover` (`fs/rc/jobs/job.go:107-115`).\n\n## 4. Proof-of-Concept \u0026 Evidence\n\n1. Configure the actual Infinite Scale creation path to a closed local endpoint.\n2. Invoke `Object.CreateUploader`.\n3. The POST returns a transport error and no response.\n4. `getTusLocationOrRetry` dereferences `resp.StatusCode` and panics.\n\nA remote endpoint can produce the same `(nil response, non-nil error)` state by accepting and resetting the connection before returning an HTTP response. TLS prevents arbitrary response modification but does not prevent the configured endpoint from closing or resetting its own connection. Refusal, DNS, TLS, proxy, and cancellation failures exercise the code defect but do not by themselves identify a remote security actor.\n\n## 5. Impact Assessment\n\nIn an unrecovered CLI or VFS upload goroutine, the panic terminates the rclone process and any unrelated work it hosts. A hostile configured endpoint can repeat the condition whenever the victim initiates a TUS upload. RC jobs are excluded from the process-wide impact because their execution boundary recovers the panic and records an error. In a one-shot process dedicated to the hostile endpoint, the incremental security impact over an ordinary transport error is limited.\n\n## 6. Remediation Guidance\n\n- Check `resp == nil` before accessing response fields.\n- Pass transport errors through the existing retry policy and return a normal error after exhaustion.\n- Test refusal, reset, timeout, DNS, TLS, proxy, and cancellation paths.\n- Add panic containment to long-lived worker goroutines as defense in depth; keep nil handling as the primary fix.",
"id": "GHSA-3x6r-wxxg-53vv",
"modified": "2026-08-05T20:26:07Z",
"published": "2026-08-05T20:26:07Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rclone/rclone/security/advisories/GHSA-3x6r-wxxg-53vv"
},
{
"type": "WEB",
"url": "https://github.com/rclone/rclone/commit/5871d98c368751a6d992ed64f8cd22cb78c44cee"
},
{
"type": "PACKAGE",
"url": "https://github.com/rclone/rclone"
},
{
"type": "WEB",
"url": "https://github.com/rclone/rclone/releases/tag/v1.75.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic"
}
GHSA-3XCM-H7JG-4XM5
Vulnerability from github – Published: 2024-02-17 00:31 – Updated: 2024-02-17 00:31StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to an out of memory condition or node reboot.
{
"affected": [],
"aliases": [
"CVE-2024-21983"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-16T23:15:07Z",
"severity": "MODERATE"
},
"details": "StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 \nare susceptible to a Denial of Service (DoS) vulnerability. Successful \nexploit by an authenticated attacker could lead to an out of memory \ncondition or node reboot.\n\n",
"id": "GHSA-3xcm-h7jg-4xm5",
"modified": "2024-02-17T00:31:38Z",
"published": "2024-02-17T00:31:38Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21983"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240216-0012"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
No mitigation information available for this CWE.
No CAPEC attack patterns related to this CWE.