VendorsNodejsundiciany version
Vulnerabilities

Nodejs undici any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
Published 2026-06-17 · Analyzed
3.7EPSS 0.002
CVE-2026-6733
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Published 2026-06-17 · Analyzed
3.7EPSS 0.002
CVE-2024-30261
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Published 2024-04-04 · Modified
3.5EPSS 0.008
← Prev2 / 2