Undici

Node.js · 46 CVEs

CVE-2026-18149
MEDIUM

undici vulnerable to Denial of Service via orphaned RetryHandler response body

Sep 4, 2026

CVE-2026-18540
LOW

undici vulnerable to downstream response splitting via retry interceptor

Sep 4, 2026

CVE-2026-19534
HIGH

undici vulnerable to Denial of Service via unrequested WebSocket subprotocol

Sep 4, 2026

CVE-2026-84890
MEDIUM

undici vulnerable to Denial of Service via unbounded decompression of compressed responses

Sep 4, 2026

CVE-2026-84933
HIGH

undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches

Sep 4, 2026

CVE-2026-84947
MEDIUM

undici vulnerable to response truncation via oversized chunked responses in the dump interceptor

Sep 4, 2026

CVE-2026-84961
CRITICAL

undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool

Sep 4, 2026

CVE-2026-85008
MEDIUM

undici vulnerable to caching and replay of unsafe HTTP method responses

Sep 4, 2026

CVE-2026-85152
HIGH

undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors

Sep 4, 2026

CVE-2026-85014
HIGH

undici vulnerable to Denial of Service via WebSocketStream unclean close

Sep 4, 2026

CVE-2026-85024
MEDIUM

undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression

Sep 4, 2026

CVE-2026-15157
MEDIUM

undici vulnerable to CRLF Injection via blob-like body 'type' property

Jul 29, 2026

CVE-2026-14643
HIGH

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

Jul 29, 2026

CVE-2026-16728
MEDIUM

undici vulnerable to downstream response desynchronization via retry interceptor

Jul 29, 2026

CVE-2026-16729
MEDIUM

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

Jul 29, 2026

CVE-2026-13697
CRITICAL

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

Jul 29, 2026

CVE-2026-11525
LOW

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

Jun 17, 2026

CVE-2026-6733
LOW

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

Jun 17, 2026

CVE-2026-9678
MEDIUM

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

Jun 17, 2026

CVE-2026-9679
MEDIUM

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Jun 17, 2026

CVE-2026-9697
HIGH

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

Jun 17, 2026

CVE-2026-6734
HIGH

undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

Jun 17, 2026

CVE-2026-9675
HIGH

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

Jun 17, 2026

CVE-2026-12151
HIGH

undici WebSocket client vulnerable to denial of service via fragment count bypass

Jun 17, 2026

CVE-2026-2229
HIGH

undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation

Mar 12, 2026

Showing 1 to 25 of 46 CVEs