undici undici是undici组织的一个HTTP客户端库。 undici 7.0.0版本至7.29.0之前版本和8.0.0版本至8.9.0之前版本存在安全漏洞,该漏洞源于缓存拦截器错误处理畸形的Cache-Control私有指令,可能导致私有响应被共享缓存存储并泄露给不同调用者,以及Cache-Control头组合问题导致未捕获的类型错误,可能终止进程。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-14643 | 5.9 MEDIUM | undici vulnerable to cross-user information disclosure via whitespace around equals in Cac |
| CVE-2026-16729 | 4.8 MEDIUM | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCoo |
| CVE-2026-16728 | 4.8 MEDIUM | undici vulnerable to downstream response desynchronization via retry interceptor |
| CVE-2026-15157 | 4.2 MEDIUM | undici vulnerable to CRLF Injection via blob-like body 'type' property |
No comments yet