VendorsNodejsundiciany version
Vulnerabilities

Nodejs undici any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2022-35949
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
Published 2022-08-12 · Modified
9.8EPSS 0.018
CVE-2026-1525
undici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Published 2026-03-12 · Analyzed
9.8EPSS 0.005
CVE-2026-13697
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
Published 2026-07-29 · Analyzed
9.1EPSS 0.005
CVE-2026-84961
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
Published 2026-09-04 · Analyzed
9.1EPSS 0.001
CVE-2026-6734
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
Published 2026-06-17 · Modified
8.8EPSS 0.003
CVE-2026-84933
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
Published 2026-09-04 · Analyzed
8.2EPSS 0.002
CVE-2023-24807
Undici vulnerable to Regular Expression Denial of Service in Headers
Published 2023-02-16 · Modified
7.5EPSS 0.013
CVE-2026-1526
undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression
Published 2026-03-12 · Modified
7.5EPSS 0.012
CVE-2026-2229
undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation
Published 2026-03-12 · Modified
7.5EPSS 0.009
CVE-2026-12151
undici WebSocket client vulnerable to denial of service via fragment count bypass
Published 2026-06-17 · Modified
7.5EPSS 0.008
CVE-2026-1528
undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client
Published 2026-03-12 · Modified
7.5EPSS 0.005
CVE-2026-22036
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Published 2026-01-14 · Modified
7.5EPSS 0.005
CVE-2026-9675
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
Published 2026-06-17 · Analyzed
7.5EPSS 0.004
CVE-2026-19534
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
Published 2026-09-04 · Analyzed
7.5EPSS 0.004
CVE-2026-85014
undici vulnerable to Denial of Service via WebSocketStream unclean close
Published 2026-09-04 · Analyzed
7.5EPSS 0.004
CVE-2026-14643
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Published 2026-07-29 · Analyzed
7.5EPSS 0.003
CVE-2026-9697
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
Published 2026-06-17 · Modified
7.4EPSS 0.005
CVE-2026-85152
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
Published 2026-09-04 · Analyzed
7.4EPSS 0.002
CVE-2022-31150
CRLF injection in request headers
Published 2022-07-19 · Modified
6.5EPSS 0.014
CVE-2023-23936
CRLF Injection in Nodejs ‘undici’ via host
Published 2023-02-16 · Modified
6.5EPSS 0.011
CVE-2022-31151
Uncleared cookies on cross-host/cross-origin redirect in undici
Published 2022-07-20 · Modified
6.5EPSS 0.007
CVE-2024-24750
Backpressure request ignored in fetch() in Undici
Published 2024-02-16 · Analyzed
6.5EPSS 0.007
CVE-2022-32210
`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.
Published 2022-07-14 · Modified
6.5EPSS 0.005
CVE-2026-16729
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
Published 2026-07-29 · Analyzed
6.5EPSS 0.002
CVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
Published 2026-07-29 · Analyzed
6.5EPSS 0.002
CVE-2026-2581
undici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads to DoS
Published 2026-03-12 · Analyzed
5.9EPSS 0.006
CVE-2026-9678
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
Published 2026-06-17 · Analyzed
5.9EPSS 0.004
CVE-2026-18149
undici vulnerable to Denial of Service via orphaned RetryHandler response body
Published 2026-09-04 · Analyzed
5.9EPSS 0.004
CVE-2026-9679
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
Published 2026-06-17 · Analyzed
5.9EPSS 0.003
CVE-2026-85024
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Published 2026-09-04 · Analyzed
5.9EPSS 0.003
CVE-2026-84890
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
Published 2026-09-04 · Analyzed
5.9EPSS 0.003
CVE-2026-15157
undici vulnerable to CRLF Injection via blob-like body 'type' property
Published 2026-07-29 · Analyzed
5.4EPSS 0.002
CVE-2022-35948
CRLF Injection in Nodejs ‘undici’ via Content-Type
Published 2022-08-13 · Modified
5.3EPSS 0.013
CVE-2026-84947
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
Published 2026-09-04 · Analyzed
5.3EPSS 0.002
CVE-2026-85008
undici vulnerable to caching and replay of unsafe HTTP method responses
Published 2026-09-04 · Analyzed
5.3EPSS 0.001
CVE-2026-1527
undici is vulnerable to CRLF Injection via upgrade option
Published 2026-03-12 · Analyzed
4.6EPSS 0.003
CVE-2024-24758
Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undici
Published 2024-02-16 · Analyzed
4.5EPSS 0.008
CVE-2024-30260
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Published 2024-04-04 · Modified
4.3EPSS 0.007
CVE-2023-45143
Undici's cookie header not cleared on cross-origin redirect in fetch
Published 2023-10-12 · Modified
3.9EPSS 0.012
CVE-2026-18540
undici vulnerable to downstream response splitting via retry interceptor
Published 2026-09-04 · Analyzed
3.7EPSS 0.002
1 / 2Next →