Node.js undici是Node.js基金会开源的一个HTTP/1.1客户端。 Node.js undici 6.17.0版本及以上版本存在资源管理错误漏洞,该漏洞源于对WebSocket分片数量未限制,可能导致恶意WebSocket服务器连续发送小或空的延续帧,造成客户端内存耗尽,导致拒绝服务。以下版本受到影响:6.17.0版本及以上版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-9675 | 7.5 HIGH | undici WebSocket client vulnerable to denial of service via cumulative fragment bypass |
| CVE-2026-6734 | 7.5 HIGH | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-9697 | 7.4 HIGH | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 Pr |
| CVE-2026-9679 | 5.9 MEDIUM | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| CVE-2026-9678 | 5.9 MEDIUM | undici vulnerable to cross-user information disclosure via shared cache whitespace bypass |
| CVE-2026-6733 | 3.7 LOW | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| CVE-2026-11525 | 3.7 LOW | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matc |
No comments yet