Back

MEDIUM

CRLF Injection in Nodejs ‘undici’ via Content-Type

Published Aug 13, 2022

Description

undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.

Affected products

Remediation

Red Hat mitigation

A possible mitigation is to sanitize user input when sending content-type headers.

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 13, 2022
Updated Apr 22, 2025
Reserved Jul 15, 2022
CISA Vulnrichment
Updated Apr 22, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 9, 2022
GHSA-F772-66G8-Q5H3