Node.js undici是Node.js基金会开源的一个HTTP/1.1客户端。 Node.js undici 7.23.0版本至7.28.0之前版本和8.0.0版本至8.5.0之前版本存在加密问题漏洞,该漏洞源于使用SOCKS5代理URI时ProxyAgent静默忽略requestTls选项,导致目标HTTPS连接回退到Node默认信任存储,可能允许中间人攻击读取和篡改HTTPS交换。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-9675 | 7.5 HIGH | undici WebSocket client vulnerable to denial of service via cumulative fragment bypass |
| CVE-2026-12151 | 7.5 HIGH | undici WebSocket client vulnerable to denial of service via fragment count bypass |
| CVE-2026-6734 | 7.5 HIGH | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-9679 | 5.9 MEDIUM | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| CVE-2026-9678 | 5.9 MEDIUM | undici vulnerable to cross-user information disclosure via shared cache whitespace bypass |
| CVE-2026-6733 | 3.7 LOW | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| CVE-2026-11525 | 3.7 LOW | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matc |
No comments yet