CVE-2026-18149
- EPSS 0.31%
- Veröffentlicht 04.09.2026 17:21:46
- Zuletzt bearbeitet 16.09.2026 20:41:26
undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the reque...
CVE-2026-18540
- EPSS 0.22%
- Veröffentlicht 04.09.2026 17:15:50
- Zuletzt bearbeitet 16.09.2026 20:41:17
undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers par...
CVE-2026-19534
- EPSS 0.39%
- Veröffentlicht 04.09.2026 17:10:05
- Zuletzt bearbeitet 16.09.2026 20:41:08
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response ...
CVE-2026-84890
- EPSS 0.25%
- Veröffentlicht 04.09.2026 17:04:28
- Zuletzt bearbeitet 11.09.2026 16:55:29
undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration opti...
CVE-2026-84933
- EPSS 0.25%
- Veröffentlicht 04.09.2026 16:59:08
- Zuletzt bearbeitet 15.09.2026 14:38:55
undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Se...
CVE-2026-84947
- EPSS 0.2%
- Veröffentlicht 04.09.2026 16:53:11
- Zuletzt bearbeitet 15.09.2026 14:30:53
undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunk...
CVE-2026-84961
- EPSS 0.15%
- Veröffentlicht 04.09.2026 16:47:55
- Zuletzt bearbeitet 15.09.2026 14:29:35
undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied check...
CVE-2026-85008
- EPSS 0.12%
- Veröffentlicht 04.09.2026 16:42:40
- Zuletzt bearbeitet 15.09.2026 14:20:11
undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed i...
CVE-2026-85152
- EPSS 0.17%
- Veröffentlicht 04.09.2026 16:36:28
- Zuletzt bearbeitet 16.09.2026 20:41:35
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cach...
CVE-2026-85014
- EPSS 0.35%
- Veröffentlicht 04.09.2026 16:30:07
- Zuletzt bearbeitet 15.09.2026 14:09:06
undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream ...