Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

undici — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in undici, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for undici, a Node.js HTTP client library. It collects publicly disclosed defects classified by weakness type, covering advisories from 2020 to 2024. Readers can use this hub to track undici's advisory history, explore specific weakness classes such as denial-of-service or improper input validation, and review the product's cumulative vulnerability profile without scrolling through individual CVE entries.

Vendor: nodejs

CVE ID Title CVSS Severity Published
CVE-2026-18149 undici vulnerable to Denial of Service via orphaned RetryHandler response body CWE-772 5.9 Medium 2026-09-04
CVE-2026-18540 undici vulnerable to downstream response splitting via retry interceptor CWE-444 3.7 Low 2026-09-04
CVE-2026-19534 undici vulnerable to Denial of Service via unrequested WebSocket subprotocol CWE-248 7.5 High 2026-09-04
CVE-2026-84890 undici vulnerable to Denial of Service via unbounded decompression of compressed responses CWE-770 5.9 Medium 2026-09-04
CVE-2026-84933 undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches CWE-200 6.5 Medium 2026-09-04
CVE-2026-84947 undici vulnerable to response truncation via oversized chunked responses in the dump interceptor CWE-20 3.7 Low 2026-09-04
CVE-2026-84961 undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool CWE-295 7.4 High 2026-09-04
CVE-2026-85008 undici vulnerable to caching and replay of unsafe HTTP method responses CWE-345 3.7 Low 2026-09-04
CVE-2026-85152 undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors CWE-346 7.4 High 2026-09-04
CVE-2026-85014 undici vulnerable to Denial of Service via WebSocketStream unclean close CWE-248 5.9 Medium 2026-09-04
CVE-2026-85024 undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression CWE-248 5.9 Medium 2026-09-04
CVE-2026-15157 undici vulnerable to CRLF Injection via blob-like body 'type' property CWE-93 4.2 Medium 2026-07-29
CVE-2026-14643 undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives CWE-436 5.9 Medium 2026-07-29
CVE-2026-16728 undici vulnerable to downstream response desynchronization via retry interceptor CWE-444 4.8 Medium 2026-07-29
CVE-2026-16729 undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields CWE-74 4.8 Medium 2026-07-29
CVE-2026-13697 undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives CWE-200 7.4 High 2026-07-29
CVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching CWE-183 3.7 Low 2026-06-17
CVE-2026-6733 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse CWE-367 3.7 Low 2026-06-17
CVE-2026-9678 undici vulnerable to cross-user information disclosure via shared cache whitespace bypass CWE-524 5.9 Medium 2026-06-17
CVE-2026-9679 undici vulnerable to HTTP header injection via Set-Cookie percent-decoding CWE-93 5.9 Medium 2026-06-17
CVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent CWE-295 7.4 High 2026-06-17
CVE-2026-6734 undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse CWE-346 7.5 High 2026-06-17
CVE-2026-9675 undici WebSocket client vulnerable to denial of service via cumulative fragment bypass CWE-400 7.5 High 2026-06-17
CVE-2026-12151 undici WebSocket client vulnerable to denial of service via fragment count bypass CWE-400 7.5 High 2026-06-17
CVE-2026-2229 undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation CWE-248 7.5 High 2026-03-12
CVE-2026-1528 undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client CWE-248 7.5 High 2026-03-12
CVE-2026-1527 undici is vulnerable to CRLF Injection via upgrade option CWE-93 4.6 Medium 2026-03-12
CVE-2026-2581 undici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads to DoS CWE-770 5.9 Medium 2026-03-12
CVE-2026-1526 undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression CWE-409 7.5 High 2026-03-12
CVE-2026-1525 undici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') CWE-444 6.5 Medium 2026-03-12

All 45 known CVE vulnerabilities affecting undici with full Chinese analysis, references, and POCs where available.