undici
18 known vulnerabilities in undici, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-84890 CVSS 5.9 medium undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of…
- CVE-2026-19534 CVSS 7.5 high undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that…
- CVE-2026-18540 CVSS 3.7 low undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response…
- CVE-2026-18149 CVSS 5.9 medium undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that…
- CVE-2026-85152 CVSS 7.4 high undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is…
- CVE-2026-85024 CVSS 5.9 medium undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream…
- CVE-2026-85014 CVSS 7.5 high undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a…
- CVE-2026-85008 CVSS 5.3 medium undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the…
- CVE-2026-84961 CVSS 9.1 critical undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value…
- CVE-2026-84947 CVSS 5.3 medium undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length…
- CVE-2026-84933 CVSS 8.2 high undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor…
- CVE-2026-15157 CVSS 5.4 medium undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the…
- CVE-2026-14643 CVSS 7.5 high undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control…
- CVE-2026-16728 CVSS 6.5 medium undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application…
- CVE-2026-16729 CVSS 6.5 medium undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from…
- CVE-2026-13697 CVSS 9.1 critical undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to…
- CVE-2026-9678 CVSS 5.9 medium Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses…
- CVE-2026-1527 CVSS 4.6 medium ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences…