CVE-2026-9697
- EPSS 0.46%
- Veröffentlicht 17.06.2026 16:46:42
- Zuletzt bearbeitet 10.09.2026 13:20:34
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured...
CVE-2026-6734
- EPSS 0.35%
- Veröffentlicht 17.06.2026 16:36:55
- Zuletzt bearbeitet 10.09.2026 13:20:30
Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, re...
CVE-2026-9675
- EPSS 0.43%
- Veröffentlicht 17.06.2026 16:20:32
- Zuletzt bearbeitet 25.06.2026 17:46:52
Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but c...
CVE-2026-12151
- EPSS 0.79%
- Veröffentlicht 17.06.2026 16:05:38
- Zuletzt bearbeitet 11.09.2026 13:17:05
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frame...
CVE-2026-2229
- EPSS 0.87%
- Veröffentlicht 12.03.2026 20:27:05
- Zuletzt bearbeitet 04.09.2026 13:18:41
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically adver...
CVE-2026-1528
- EPSS 0.49%
- Veröffentlicht 12.03.2026 20:21:57
- Zuletzt bearbeitet 04.09.2026 13:18:18
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches ...
CVE-2026-1527
- EPSS 0.26%
- Veröffentlicht 12.03.2026 20:17:18
- Zuletzt bearbeitet 20.03.2026 15:49:31
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to...
CVE-2026-2581
- EPSS 0.57%
- Veröffentlicht 12.03.2026 20:13:19
- Zuletzt bearbeitet 18.03.2026 13:37:08
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in...
CVE-2026-1526
- EPSS 1.15%
- Veröffentlicht 12.03.2026 20:08:05
- Zuletzt bearbeitet 04.09.2026 13:18:17
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incomin...
CVE-2026-1525
- EPSS 0.49%
- Veröffentlicht 12.03.2026 19:56:55
- Zuletzt bearbeitet 19.03.2026 17:29:34
Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the...