Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-9697— undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

Quick assessment

Affected
undici undici
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Node.js undici是Node.js基金会开源的一个HTTP/1.1客户端。 Node.js undici 7.23.0版本至7.28.0之前版本和8.0.0版本至8.5.0之前版本存在加密问题漏洞,该漏洞源于使用SOCKS5代理URI时ProxyAgent静默忽略requestTls选项,导致目标HTTPS连接回退到Node默认信任存储,可能允许中间人攻击读取和篡改HTTPS交换。

CVSS 7.4 · High EPSS 0.55% · P44

Affected Version Matrix 4

VendorProduct Version RangeStatus
undici undici 7.23.0< 7.28.0 affected
7.28.0 unaffected
8.0.0< 8.5.0 affected
8.5.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9697

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
Source: CVE Program / CVE List V5
Vulnerability Description
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings. Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange. Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Node.js undici 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Node.js undici是Node.js基金会开源的一个HTTP/1.1客户端。 Node.js undici 7.23.0版本至7.28.0之前版本和8.0.0版本至8.5.0之前版本存在加密问题漏洞,该漏洞源于使用SOCKS5代理URI时ProxyAgent静默忽略requestTls选项,导致目标HTTPS连接回退到Node默认信任存储,可能允许中间人攻击读取和篡改HTTPS交换。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
undici undici 7.23.0 ~ 7.28.0 -

II. Public POCs for CVE-2026-9697

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 9355 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-9697

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-9697 (1)

Same Patch Batch · undici · 2026-06-17 · 8 CVEs total

CVE-2026-9675 7.5 HIGH undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2026-12151 7.5 HIGH undici WebSocket client vulnerable to denial of service via fragment count bypass
CVE-2026-6734 7.5 HIGH undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
CVE-2026-9679 5.9 MEDIUM undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-9678 5.9 MEDIUM undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
CVE-2026-6733 3.7 LOW undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-11525 3.7 LOW undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matc

IV. Related Vulnerabilities

V. Comments for CVE-2026-9697

No comments yet


Leave a comment