undici undici是undici组织的一个HTTP客户端库。 undici 6.28.0之前版本、7.0.0版本至7.29.0之前版本和8.0.0版本至8.9.0之前版本存在输入验证错误漏洞,该漏洞源于未验证类blob请求体的type属性,可能导致攻击者注入CRLF序列并附加任意HTTP头,从而走私第二个请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13697 | 7.4 HIGH | undici vulnerable to cross-user information disclosure and parse-time crash via degenerate |
| CVE-2026-14643 | 5.9 MEDIUM | undici vulnerable to cross-user information disclosure via whitespace around equals in Cac |
| CVE-2026-16729 | 4.8 MEDIUM | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCoo |
| CVE-2026-16728 | 4.8 MEDIUM | undici vulnerable to downstream response desynchronization via retry interceptor |
No comments yet