Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

undici — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in undici, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for undici, a Node.js HTTP client library. It collects publicly disclosed defects classified by weakness type, covering advisories from 2020 to 2024. Readers can use this hub to track undici's advisory history, explore specific weakness classes such as denial-of-service or improper input validation, and review the product's cumulative vulnerability profile without scrolling through individual CVE entries.

Vendor: nodejs

CVE ID Title CVSS Severity Published
CVE-2026-22036 Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion CWE-770 5.9 Medium 2026-01-14
CVE-2025-47279 undici Denial of Service attack via bad certificate data CWE-401 3.1 Low 2025-05-15
CVE-2025-22150 Undici Uses Insufficiently Random Values CWE-330 6.8 Medium 2025-01-21
CVE-2024-38372 Undici vulnerable to data leak when using response.arrayBuffer() CWE-201 2.0 Low 2024-07-08
CVE-2024-30260 Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline CWE-285 3.9 Low 2024-04-04
CVE-2024-30261 Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect CWE-284 2.6 Low 2024-04-04
CVE-2024-24750 Backpressure request ignored in fetch() in Undici CWE-400 6.5 Medium 2024-02-16
CVE-2024-24758 Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undici CWE-200 3.9 Low 2024-02-16
CVE-2023-45143 Undici's cookie header not cleared on cross-origin redirect in fetch CWE-200 3.9 Low 2023-10-12
CVE-2023-23936 CRLF Injection in Nodejs ‘undici’ via host CWE-93 6.5 Medium 2023-02-16
CVE-2023-24807 Undici vulnerable to Regular Expression Denial of Service in Headers CWE-20 7.5 High 2023-02-16
CVE-2022-35948 CRLF Injection in Nodejs ‘undici’ via Content-Type CWE-93 5.3 Medium 2022-08-13
CVE-2022-35949 `undici.request` vulnerable to SSRF using absolute URL on `pathname` CWE-918 5.3 Medium 2022-08-12
CVE-2022-31151 Uncleared cookies on cross-host/cross-origin redirect in undici CWE-601 3.7 Low 2022-07-20
CVE-2022-31150 CRLF injection in request headers CWE-93 5.3 Medium 2022-07-19

All 45 known CVE vulnerabilities affecting undici with full Chinese analysis, references, and POCs where available.