← nodejs

nodejs / undici

22 known vulnerabilities in nodejs undici.

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-1526 Medium 1.2% 7.5 The undici WebSocket client is vulnerable to a denial-of-service attack via unbo…
CVE-2026-2229 Medium 0.9% 7.5 ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack du…
CVE-2026-12151 Medium 0.8% 7.5 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative by…
CVE-2026-1528 Medium 0.5% 7.5 ImpactA server can reply with a WebSocket frame using the 64-bit length form and…
CVE-2026-13697 Medium 0.5% 7.4 undici's cache interceptor mishandles malformed Cache-Control private directives…
CVE-2026-9697 Medium 0.5% 7.4 Impact: undici's ProxyAgent silently drops the requestTls option when configured…
CVE-2026-19534 Medium 0.4% 7.5 undici's WebSocket client crashes the whole Node.js process during the opening h…
CVE-2026-6734 Medium 0.3% 7.5 Impact: When using Socks5ProxyAgent, undici reuses a single connection pool acro…
CVE-2026-85152 Medium 0.2% 7.4 undici 8.10.0 omits the destination origin from the cache and request-deduplicat…
CVE-2026-84961 Medium 0.1% 7.4 undici's BalancedPool constructor passes its entire options object through an in…
CVE-2026-85014 Low 0.4% 5.9 undici's experimental WebSocketStream client crashes the whole Node.js process w…
CVE-2026-18149 Low 0.4% 5.9 undici's retry handler can leave an already-exposed response body pending foreve…
CVE-2026-14643 Low 0.3% 5.9 undici's cache interceptor mishandles optional whitespace placed around the equa…
CVE-2026-85024 Low 0.3% 5.9 undici bundles a WebSocket client whose permessage-deflate size-limit cleanup re…
CVE-2026-84890 Low 0.3% 5.9 undici's decompress interceptor decompresses response bodies according to the un…
CVE-2026-84933 Low 0.2% 6.5 undici's cache interceptor does not handle the Set-Cookie response header anywhe…
CVE-2026-18540 Low 0.2% 3.7 undici's retry interceptor can append the body of a ranged retry response to byt…
CVE-2026-84947 Low 0.2% 3.7 undici's dump interceptor reads and discards a response body up to a configurabl…
CVE-2026-15157 Low 0.2% 4.2 undici does not validate the type property of a duck-typed blob-like request bod…
CVE-2026-16729 Low 0.2% 4.8 undici's setCookie function does not fully sanitize cookie attributes. In undici…
CVE-2026-16728 Low 0.2% 4.8 undici's retry interceptor can deliver a response whose body length does not mat…
CVE-2026-85008 Low 0.1% 3.7 undici's cache interceptor documents that only safe HTTP methods are cached, but…