Node.js undici是Node.js基金会开源的一个HTTP/1.1客户端。 Node.js undici 6.26.0之前版本、7.28.0之前版本和8.5.0之前版本存在输入验证错误漏洞,该漏洞源于解析Set-Cookie标头时,将包含Strict、Lax或None子字符串的SameSite属性值接受为标准值,而非严格执行RFC 6265的精确匹配,可能导致恶意服务器将cookie的SameSite策略弱化为更宽松的设置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9675 | 7.5 HIGH | undici WebSocket client vulnerable to denial of service via cumulative fragment bypass |
| CVE-2026-12151 | 7.5 HIGH | undici WebSocket client vulnerable to denial of service via fragment count bypass |
| CVE-2026-6734 | 7.5 HIGH | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-9697 | 7.4 HIGH | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 Pr |
| CVE-2026-9679 | 5.9 MEDIUM | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| CVE-2026-9678 | 5.9 MEDIUM | undici vulnerable to cross-user information disclosure via shared cache whitespace bypass |
| CVE-2026-6733 | 3.7 LOW | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
No comments yet