Nodejs

Undici

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Veröffentlicht 17.06.2026 16:46:42
  • Zuletzt bearbeitet 10.09.2026 13:20:34

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured...

  • EPSS 0.35%
  • Veröffentlicht 17.06.2026 16:36:55
  • Zuletzt bearbeitet 10.09.2026 13:20:30

Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, re...

  • EPSS 0.43%
  • Veröffentlicht 17.06.2026 16:20:32
  • Zuletzt bearbeitet 25.06.2026 17:46:52

Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but c...

  • EPSS 0.79%
  • Veröffentlicht 17.06.2026 16:05:38
  • Zuletzt bearbeitet 11.09.2026 13:17:05

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frame...

  • EPSS 0.87%
  • Veröffentlicht 12.03.2026 20:27:05
  • Zuletzt bearbeitet 04.09.2026 13:18:41

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically adver...

  • EPSS 0.49%
  • Veröffentlicht 12.03.2026 20:21:57
  • Zuletzt bearbeitet 04.09.2026 13:18:18

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches ...

  • EPSS 0.26%
  • Veröffentlicht 12.03.2026 20:17:18
  • Zuletzt bearbeitet 20.03.2026 15:49:31

ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to...

  • EPSS 0.57%
  • Veröffentlicht 12.03.2026 20:13:19
  • Zuletzt bearbeitet 18.03.2026 13:37:08

This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in...

  • EPSS 1.15%
  • Veröffentlicht 12.03.2026 20:08:05
  • Zuletzt bearbeitet 04.09.2026 13:18:17

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incomin...

  • EPSS 0.49%
  • Veröffentlicht 12.03.2026 19:56:55
  • Zuletzt bearbeitet 19.03.2026 17:29:34

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the...