Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

undici — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting undici. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Undici is a Node.js HTTP/1.1 client library primarily used for making HTTP requests in server-side applications. Historically, it has been vulnerable to several remote code execution (RCE) and cross-site scripting (XSS) flaws, often stemming from improper input validation and insecure default configurations. The library has faced security incidents including path traversal vulnerabilities and request smuggling issues due to inconsistent header handling. While its core functionality is straightforward, undici's security track record shows recurring issues in request parsing and URL handling, requiring careful implementation and regular updates to mitigate risks.

Top products by undici: undici
CVE IDTitleCVSSSeverityPublished
CVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching — undiciCWE-183 3.7 Low2026-06-17
CVE-2026-6733 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse — undiciCWE-367 3.7 Low2026-06-17
CVE-2026-9678 undici vulnerable to cross-user information disclosure via shared cache whitespace bypass — undiciCWE-524 5.9 Medium2026-06-17
CVE-2026-9679 undici vulnerable to HTTP header injection via Set-Cookie percent-decoding — undiciCWE-93 5.9 Medium2026-06-17
CVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent — undiciCWE-295 7.4 High2026-06-17
CVE-2026-6734 undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse — undiciCWE-346 7.5 High2026-06-17
CVE-2026-9675 undici WebSocket client vulnerable to denial of service via cumulative fragment bypass — undiciCWE-400 7.5 High2026-06-17
CVE-2026-12151 undici WebSocket client vulnerable to denial of service via fragment count bypass — undiciCWE-400 7.5 High2026-06-17
CVE-2026-2229 undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation — undiciCWE-248 7.5 High2026-03-12
CVE-2026-1528 undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client — undiciCWE-248 7.5 High2026-03-12
CVE-2026-1527 undici is vulnerable to CRLF Injection via upgrade option — undiciCWE-93 4.6 Medium2026-03-12
CVE-2026-2581 undici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads to DoS — undiciCWE-770 5.9 Medium2026-03-12
CVE-2026-1526 undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression — undiciCWE-409 7.5 High2026-03-12
CVE-2026-1525 undici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') — undiciCWE-444 6.5 Medium2026-03-12

This page lists every published CVE security advisory associated with undici. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.