VendorsNodejsundiciall versions
Vulnerabilities

Nodejs undici

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2026-18540
undici vulnerable to downstream response splitting via retry interceptor
Published 2026-09-04 · Analyzed
3.7EPSS 0.002
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
Published 2026-06-17 · Analyzed
3.7EPSS 0.002
CVE-2024-30261
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Published 2024-04-04 · Modified
3.5EPSS 0.008
← Prev2 / 2