CRLF Injection in Nodejs ‘undici’ via Content-Type
Published Aug 13, 2022
5.3
MEDIUMCVSS 3.1
EPSS 1.27%
Description
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
Affected products
-
- Version =< 5.8.0StatusaffectedConstraints-
- Version
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-ui-rhel8
Affected
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-ui-rhel8 | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel8 | Affected | n/a |
undici
npm
Introduced 0 Fixed 5.8.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | undici | 0 | 5.8.2 |
Remediation
Red Hat mitigation
A possible mitigation is to sanitize user input when sending content-type headers.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 22, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.27% (0.01266) | 68.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.20% (0.01203) | 64.12th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.14% (0.00143) | 31.93th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00102) | 43.40th | v3 (v2023.03.01) |
| May 22, 2024 | 0.08% (0.00079) | 33.87th | v3 (v2023.03.01) |
| Jan 24, 2024 | 0.08% (0.00077) | 31.86th | v3 (v2023.03.01) |
| Jul 14, 2023 | 0.07% (0.00067) | 27.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00059) | 22.71th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Feb 23, 2023 | 0.95% (0.00954) | 36.27th | v2 (v2022.01.01) |
| Aug 17, 2022 | 0.95% (0.00954) | 34.25th | v2 (v2022.01.01) |
| Aug 14, 2022 | 0.89% (0.00890) | 28.33th | v2 (v2022.01.01) |
References (8)
- https://access.redhat.com/security/cve/CVE-2022-35948 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2121101 Issue Tracking
- https://github.com/advisories/GHSA-f772-66g8-q5h3 Advisory
- https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80 PatchThird Party Advisory
- https://github.com/nodejs/undici/releases/tag/v5.8.2 Release NotesThird Party Advisory
- https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-35948
- https://www.cve.org/CVERecord?id=CVE-2022-35948
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-35948 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2121101 | Issue Tracking | |
| https://github.com/advisories/GHSA-f772-66g8-q5h3 | Advisory | |
| https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80 | PatchThird Party Advisory | |
| https://github.com/nodejs/undici/releases/tag/v5.8.2 | Release NotesThird Party Advisory | |
| https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3 | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-35948 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-35948 |
Change history (0)
No recorded changes yet.