Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

undici — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting undici. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Undici is a Node.js HTTP/1.1 client library primarily used for making HTTP requests in server-side applications. Historically, it has been vulnerable to several remote code execution (RCE) and cross-site scripting (XSS) flaws, often stemming from improper input validation and insecure default configurations. The library has faced security incidents including path traversal vulnerabilities and request smuggling issues due to inconsistent header handling. While its core functionality is straightforward, undici's security track record shows recurring issues in request parsing and URL handling, requiring careful implementation and regular updates to mitigate risks.

Top products by undici: undici
CVE ID Title CVSS Severity Published
CVE-2026-18149 undici vulnerable to Denial of Service via orphaned RetryHandler response body — undici CWE-772 5.9 Medium 2026-09-04
CVE-2026-18540 undici vulnerable to downstream response splitting via retry interceptor — undici CWE-444 3.7 Low 2026-09-04
CVE-2026-19534 undici vulnerable to Denial of Service via unrequested WebSocket subprotocol — undici CWE-248 7.5 High 2026-09-04
CVE-2026-84890 undici vulnerable to Denial of Service via unbounded decompression of compressed responses — undici CWE-770 5.9 Medium 2026-09-04
CVE-2026-84933 undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches — undici CWE-200 6.5 Medium 2026-09-04
CVE-2026-84947 undici vulnerable to response truncation via oversized chunked responses in the dump interceptor — undici CWE-20 3.7 Low 2026-09-04
CVE-2026-84961 undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool — undici CWE-295 7.4 High 2026-09-04
CVE-2026-85008 undici vulnerable to caching and replay of unsafe HTTP method responses — undici CWE-345 3.7 Low 2026-09-04
CVE-2026-85152 undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors — undici CWE-346 7.4 High 2026-09-04
CVE-2026-85014 undici vulnerable to Denial of Service via WebSocketStream unclean close — undici CWE-248 5.9 Medium 2026-09-04
CVE-2026-85024 undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression — undici CWE-248 5.9 Medium 2026-09-04
CVE-2026-15157 undici vulnerable to CRLF Injection via blob-like body 'type' property — undici CWE-93 4.2 Medium 2026-07-29
CVE-2026-14643 undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives — undici CWE-436 5.9 Medium 2026-07-29
CVE-2026-16728 undici vulnerable to downstream response desynchronization via retry interceptor — undici CWE-444 4.8 Medium 2026-07-29
CVE-2026-16729 undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — undici CWE-74 4.8 Medium 2026-07-29
CVE-2026-13697 undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives — undici CWE-200 7.4 High 2026-07-29
CVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching — undici CWE-183 3.7 Low 2026-06-17
CVE-2026-6733 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse — undici CWE-367 3.7 Low 2026-06-17
CVE-2026-9678 undici vulnerable to cross-user information disclosure via shared cache whitespace bypass — undici CWE-524 5.9 Medium 2026-06-17
CVE-2026-9679 undici vulnerable to HTTP header injection via Set-Cookie percent-decoding — undici CWE-93 5.9 Medium 2026-06-17
CVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent — undici CWE-295 7.4 High 2026-06-17
CVE-2026-6734 undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse — undici CWE-346 7.5 High 2026-06-17
CVE-2026-9675 undici WebSocket client vulnerable to denial of service via cumulative fragment bypass — undici CWE-400 7.5 High 2026-06-17
CVE-2026-12151 undici WebSocket client vulnerable to denial of service via fragment count bypass — undici CWE-400 7.5 High 2026-06-17
CVE-2026-2229 undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation — undici CWE-248 7.5 High 2026-03-12
CVE-2026-1528 undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client — undici CWE-248 7.5 High 2026-03-12
CVE-2026-1527 undici is vulnerable to CRLF Injection via upgrade option — undici CWE-93 4.6 Medium 2026-03-12
CVE-2026-2581 undici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads to DoS — undici CWE-770 5.9 Medium 2026-03-12
CVE-2026-1526 undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression — undici CWE-409 7.5 High 2026-03-12
CVE-2026-1525 undici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') — undici CWE-444 6.5 Medium 2026-03-12

This page lists every published CVE security advisory associated with undici. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.