Vulnerability in hash project
area/blockslang/javascriptcategory/bug
### Block impacted
undici package
### Describe the bug
while working in hash Project, I found a vulnerability. [CVE-2026-22036](https://vulert.com/vuln-db/undici-has-an-unbounded-decompression-chain-in-http-responses-on-node-js-fetch-api-via-content-encod---) is a resource exhaustion vulnerability in the Undici package where unbounded chained HTTP decompression is allowed via the fetch() API. A malicious server can abuse multiple Content-Encoding layers to cause excessive CPU and memory usage, potentially leading to application crashes or degraded performance.
[CVE Link](https://vulert.com/vuln-db/undici-has-an-unbounded-decompression-chain-in-http-responses-on-node-js-fetch-api-via-content-encod---)
[CVE Report](https://vulert.com/vuln-scan/list/4d599b60-da0b-400b-ad88-444cd8b5afe7?sort_order=desc&sort_by=created_at)
### To reproduce
_No response_
### Expected behavior
_No response_
### Device
_No response_
### Operating system
_No response_
### Browser
_No response_
### Additional context
_No response_
关闭于 2026-01-15 1 条评论